Hikyo documentation
Learn Hikyo from first run through production operation, automation, and recovery.
Hikyo is a self-hosted control plane for validated secrets and configuration.
Every value is explicitly set or absent in every environment. There is no
inheritance, hidden fallback, or paid operational core.
Choose the path that matches what you need to do now.
Getting started
Build the binary, run a local instance, and create the first administrator.
Installation
Choose between local evaluation, a reusable source build, and production preparation.
Create your first project
Create environments, declare a key, and save your first validated value.
Self-hosting
Define the datastore, root key, network, origin, and backup boundaries.
Operate and recover
Back up, restore, reconcile access, upgrade, and diagnose an instance.
Documentation map
| If you want to… | Start here |
|---|---|
| Understand release scope and remaining gates | Roadmap to 1.0 |
| Install Hikyo | Installation |
| Build the binary | Build from source |
| Complete a first workflow | Create your first project |
| Understand the system boundary | Architecture |
| Model teams and applications | Hierarchy |
| Declare and change values safely | Values and secrets |
| Configure local CLI targets | Contexts and targets |
| Connect a workload | Machine identities |
| Secure or recover an account | Account security |
| Connect an identity provider | SAML or SCIM |
| Configure a server | Configuration |
| Recover from an archive | Backup and restore |
| Look up commands or routes | CLI reference or HTTP API |
0.x development
Hikyo interfaces are not frozen until the 1.0.0 release gate passes.
Prerelease builds are unsupported. These docs track the main branch.
Load-bearing policy
- Security — private reporting and disclosure timelines.
- Support — exactly one supported release line.
- Governance — public authority and amendment rules.
- Implementation status — machine-checked current capability and obligation state.
- License — MPL-2.0 and the permanent no-enterprise-directory pledge.