Platform architecture
Lamassu components and how control, keys, issuance and devices relate.
Lamassu deploys as a set of independent services. This separation keeps every component from needing direct access to private keys and lets each capability scale according to load.
Control plane
The console and the APIs manage authorities, certificates, DMSs, devices, alerts and configuration. Domain events allow connectors and automations to react to changes without continuously polling the platform.
Key custody and cryptographic operations
The KMS offers a common interface over software engines, PKCS#11 and cloud providers. The selected engine keeps the key or delegates the cryptographic operation without the other services knowing its implementation.
Issuance and enrollment
The CA service issues certificates and maintains the relationship with its authority. The DMS applies the enrollment rules and exposes the EST flowsflows of the configured protocol — EST or CMP — so a device can request or renew an identity.
Status and validation
Device Manager keeps the operational view of the device and its history. The Validation Authority publishes OCSP and CRLs so other systems can decide whether to trust a presented certificate.
Platform dependencies
In a self-managed deployment, Lamassu uses PostgreSQL for persistence, RabbitMQ for messaging and an OIDC provider for authentication. See the deployment architecture for how the services are published on Kubernetes.