Back to catalog
Sealed pack — prompts are encrypted. Sidereal Pro required to install.

sidereal-bastion

Advanced security operations and fleet management for Sidereal. Monitor credential expiry before keys lapse, detect TCC permission drift, audit network exposure and fleet trust boundaries. Coordinate rolling upgrades across your fleet, forecast capacity constraints, and verify backup freshness — all with structured vault reports and ntfy alerting.

pack certified v1.1.0 sealed spec 1.6 Proprietary
AuthorSidereal
Skills9
Agents2
Workflows2

Skill Categories

reportreviewsync

Required Services

vault
readsearchcreateappend

Data Transparency

Reads
vault
Writes
vault
Stores nothing
Phones home No

Content

Agents 2

secops-operatoroperator
fleet-operatoroperator

Skills 9

credential-expiry-watchScan credentials and API keys for approaching expiry
secops-operatorreviewon-demand
tcc-drift-monitorDetect TCC privacy grant changes since last snapshot
secops-operatorreviewon-demand
network-exposure-scanAudit listening ports, firewall rules, and Tailscale ACLs
secops-operatorreviewon-demand
fleet-trust-auditVerify fleet peer bearer tokens and enrollment markers
secops-operatorreviewon-demand
dispatch-analyticsAggregate dispatch metrics across the fleet
fleet-operatorreporton-demand
upgrade-coordinatorOrchestrate rolling self-upgrade across fleet peers
fleet-operatorsyncon-demand
capacity-forecastTrack resource usage and project capacity constraints
fleet-operatorreporton-demand
mcp-lifecycleDetect unused or unhealthy MCP servers
fleet-operatorreviewon-demand
backup-verificationVerify vault sync, snapshot, and config backup freshness
fleet-operatorsyncon-demand

Workflows 2

security-sweepFull security posture review — credentials, TCC, network, fleet trust
4 steps
fleet-healthComplete platform status — MCP lifecycle, capacity, backups, dispatch metrics
4 steps

Install

sidereal install sidereal-bastion

Requires Sidereal Pro