Skip to content
Castellan
Toller's icon

Overview · Toller

Read as

The Toller, which checks what came through the gate

What the Toller looks at every hour (new dependencies and tools, dev servers open to your network, secrets left in the open), how it keeps a secret without its value, and the two fixes it makes when you tick them.

Article
1701
Applies to
Toller 0.1.1
Last reviewed
For
For developers
Written for Toller 0.1.1. Toller is at 0.1.2 now (1 small release since: what changed).

What it is#

Where the Porter looks after what comes onto the PC, the Toller looks at what came into the projects and the tools you build them with. Every hour it says what's new since the last look, and what's been left where anyone could pick it up.

It's a developer agent, and holds the Porter's office: once it's hired, the Porter stays on duty behind it. See Hiring, switching and letting staff go.

What it looks at#

AreaWhat it finds
What entered your projectsNew, updated and removed dependencies in your repositories' lockfiles, flagging the ones that run a script when installed, and names one letter away from a much more popular package.
What entered your toolsNew editor extensions and who published them, global npm, pip, cargo and dotnet tools, folders added to PATH, git hooks, and changes to git's own settings.
Dev servers open to your networkServers run by Node, Python, .NET, Java, Docker and other developer runtimes that listen on every network, not only on this PC.
Secrets left in the openAPI keys, tokens and private keys in your repositories, your shell histories and the text files in Downloads, with how far each went: pushed, committed, or not yet.

The details are in What the Toller checks.

How it works#

A round every hour, or on Run now. A round reads only what changed since the last one, by each file's size and time, so after the first look it's quick.

Nothing goes over the network. It reads lockfiles, folders and settings on this PC, and asks no registry.

Code decides everything. There's no model: each finding is a rule's, with what it is, where, why it matters and what to do.

Secrets are never kept#

What it keeps of a secret is its kind, its file and line, when it was first seen, and a fingerprint made with a key that never leaves this PC. That's enough to tell one secret from another without the value. Nothing it shows, writes or logs holds a value, and a command line that holds one isn't shown.

You decide what changes#

Each finding has Seen, which quiets it. A change (a new extension, a new dependency) is let go once seen; something still there (a secret, an open server) stays quiet while it's there, as Seen, leave it. Mark all seen does a whole area.

Two fixes can be ticked, on the findings they fit:

  • Add to .gitignore: adds a file to its project's .gitignore.
  • Take the line out of the history: takes a secret's lines out of a shell history.

It never rotates a key, deletes a file, or rewrites git's history: those are yours.

Its home page#

The Toller's page is at http://toller.localhost:21818/, and Open on the Porter's card in Castellan goes there. Each area shows what it found, worst first, or "nothing to report", and the changes of the last rounds. Settings and Run now are in the title bar.

Getting started#

  1. Hire it in Castellan, from the Porter's card. It's included in the Workshop license.
  2. Take its tour. It needs nothing from you to start: it finds the repositories Castellan and Reeve know, and the usual folders.
  3. Look at Secrets left in the open first. Rotate anything pushed.

Is this page right?

If something on it is wrong or out of date, tell us and we'll fix the page.

Still stuck? Write to support@castellan-software.com and mention article 1701. Every version of Toller, and what changed in it, is in its release notes.