OFFICIAL PRODUCT SURFACE / INDUSTRIAL SYSTEM Production control plane · Official release published · Client integration pending

CLIENT × RESIDENT AGENT

Keep the SSH working context online

A native client and resident agent keep persistent terminals, monitoring, files, and system tools in the context of the same host.

I/O MATRIX / PLATFORM

5 SLOTS
W

Windows

Desktop client

See downloads for live records
L

Linux

Independent client

See downloads for live records
A

Android

Mobile companion

See downloads for live records
m

macOS

Independent desktop client

Planned · Downloads not open
i

iOS

Independent mobile companion

Planned · Downloads not open

01 / HOW IT WORKS

Make the client and agent boundary obvious

The client authenticates and initiates, SSH is the only entry point, and the resident agent exposes structured capabilities through a server-local socket.

01 NODE 01

Native client

Hosts, credentials, trust, and operation entry points stay local.

CLIENT
02 LINK 02

SSH tunnel

Reuse SSH authentication and encryption without a new public port.

PURE SSH
03 CORE 03

Resident agent

Listen only on the server-local socket and provide structured capabilities.

AGENT
04 STATE 04

tmux / redb

Terminal context and monitoring history persist on the server.

SERVER STATE
05 TOOLS 05

Files and systems

Reliable transfers and system actions use explicit protocols.

STRUCTURED
06 PURE SSH

Works without the agent

Standard terminals, port forwarding, and access grants keep a native SSH path.

Fallback boundary
07 RESIDENT AGENT

Client × agent integration

Persistent terminals, monitoring history, files, AI, systems, and apps use the structured protocol.

Primary path

02 / CAPABILITIES

One workspace, nine clearly bounded modules

Every module states its dependency and result. The product docs continue with architecture, boundaries, interfaces, and verification.

01 MIXED

Host management

Connections, authentication, host keys, and real reachability results.

Connection entry
02 MIXED

Terminal

Choose persistent tmux or a standard SSH PTY by task.

Resume context
03 AGENT

Monitoring

Snapshots, live subscriptions, history, and top processes.

Structured status
04 AGENT

Files

Browse, search, edit, and transfer with integrity checks.

Same host context
05 PURE SSH

Port forwarding

Map server-reachable ports safely to the client machine.

Native SSH
06 AGENT

AI assistant

Invoke structured tools behind permission, confirmation, and audit gates.

Bring your model
07 AGENT

System management

Read system facts and manage processes or firewalls explicitly.

Visible actions
08 AGENT

Application center

Focus on Docker, common apps, and systemd services.

Capability modules
09 PURE SSH

Access grants

Issue isolated access keys and revoke them by stable marker.

Least access

03 / FIRST RUN

From the first host to a complete workflow

Tutorials form an executable path from first connection to daily operations instead of a loose article collection.

01 STEP 01

Add a host

Complete SSH authentication and host-key trust.

Verify connection
02 STEP 02

Deploy the agent

Probe server architecture and select the matching agent and tmux pair.

Paired deployment
03 STEP 03

Persistent terminal

Disconnect deliberately, then verify task and screen recovery.

tmux
04 STEP 04

Monitoring history

Inspect live detail, historical ranges, and processes.

redb
05 STEP 05

File transfer

Upload or download and verify integrity results.

Chunk verification
06 STEP 06

AI assistant

Use your own model and begin with read-only diagnosis.

Permission gate

04 / PLATFORMS

Five platforms with independent positions

Public Windows, Linux, and Android status comes from real release records. macOS and iOS keep separate, explicitly planned positions.

01 See downloads for live records

Windows

Complete desktop operations

Independent native client
02 See downloads for live records

Linux

Desktop operations and local builds

Independent native client
03 See downloads for live records

Android

Mobile inspection and lightweight actions

Independent mobile client
04 Planned · Downloads not open

macOS

Future desktop client

Reserved independent platform boundary
05 Planned · Downloads not open

iOS

Future mobile companion

Reserved independent platform boundary

05 / SECURITY BOUNDARY

A direct SSH data plane and restrained cloud control plane

The two paths stay separate: Creation Cloud never enters the SSH data plane between the client and your server.

01 SSH DATA PLANE

Client to user server

The agent uses a local socket, host-key changes require confirmation, and SSH, tmux, or user processes are never ended without authorization.

Cloud is not in this path
02 CLOUD CONTROL PLANE

Accounts, devices, and optional sync

Only a non-sensitive allowlist can sync. Vault encryption stays on trusted clients and the service stores versioned ciphertext envelopes only.

No plaintext sensitive data

07 / CREATION CLOUD

Accounts support devices and sync, never SSH

The Creation Cloud control plane is deployed on the production server with accounts, devices, sync, model metadata, encrypted vault envelopes, releases, downloads, and administration. Production client integration ships separately.

01 ACCOUNT

Profile and security

Account status, security settings, and password boundaries.

Account password ≠ vault password
02 DEVICE

Devices

Register, rename, and revoke trusted devices.

No SSH host records
03 SYNC

Sync

Revisions, conflicts, and non-sensitive allowlist results.

Unknown fields denied
04 MODEL

Models

Sync credential-free model metadata, defaults, and order.

API keys reference ciphertext
05 VAULT

Vault

Show ciphertext versions and device-wrapper status only.

Server cannot decrypt
06 RELEASE

Downloads

Expose compatible releases, sources, and download history.

Real records

08 / FAQ

Answer the questions that decide adoption

The home page keeps only high-value decision questions; the FAQ page carries the full explanation.

FAQ 01Does Creation Cloud proxy SSH?

No. The SSH data plane remains direct from the client to your server. Cloud only provides account, device, and optional sync controls.

FAQ 02Can I use Creation-SSH without the agent?

A standard SSH terminal, port forwarding, and access grants remain available. Persistent sessions, monitoring, and structured management depend on the agent.

FAQ 03Are host addresses and private keys uploaded?

Not in plaintext. Host records, passwords, private keys, known_hosts, terminal content, and command history are outside the sync allowlist.

FAQ 04Is the vault password the account password?

No. The account password signs you in. The vault password derives encryption keys only on trusted clients and is never uploaded.

FAQ 05How can I verify a download?

Formal download entries expose platform, architecture, source, file size, and SHA256 for verification before installation.

FAQ 06Is Android a full desktop copy?

No. Android is a mobile companion focused on inspection, lightweight actions, and continuity with desktop workflows.

SEARCH TOPICS / CONTENT MAP

Related SSH topics

  • SSH
  • AI-SSH

NEXT STEP / START HERE

Choose a platform, then start with the first tutorial

Capabilities, platform status, and downloads always follow real implementation, deployment, and release records.

MOBILE ACCESS / QR QR code awaiting admin upload
Scan entry Click the card to toggle size