After twenty-five years in infrastructure, I have seen the same story play out hundreds of times: capable teams spending weeks connecting observability and security tools before those tools answer one useful question.

The answer is not another opaque platform. It is a better starting point.

Updated July 2026: the family has grown from five projects to twelve. This post now reflects the complete suite.

What In a Box means

In a Box Tools is a family of inspectable, self-hosted infrastructure blueprints. Each project starts with an operational question, packages proven open-source components, and keeps the configuration and trade-offs visible.

The goal is not “zero complexity.” Infrastructure does not work that way. The goal is visible complexity with useful defaults: something an engineer can deploy, inspect, change, and still understand when it fails.

The complete family

Context and operations

Detection and response

Posture and prioritization

Trust and access

  • IIB — Identity in a Box packages Authentik with generated secrets, health metrics, and an operational dashboard.
  • PIB — PKI in a Box packages step-ca, ACME support, trust bootstrap, certificate probing, and expiry monitoring.

Unified suite

Every project remains independently deployable. XIB unifies the decision surface; it does not flatten five security domains into a fake single database.

The principles

  1. Outcomes first — begin with the question, not the container list.
  2. Opinionated, not opaque — provide useful defaults without hiding how the system works.
  3. Local by default — keep telemetry, findings, identities, and asset data under the operator’s control.
  4. Honest boundaries — a blueprint reduces integration toil; it does not replace backups, capacity planning, threat modeling, or responders.
  5. Open source — inspect it, fork it, run one project, or combine several.

Browse the complete toolkit or inspect every repository on GitHub.