Skip to content

Status

Version 0.5.0 is the whole application as planned, and the first release since the repository stood alone. The observed half was built in twelve review-gated subphases whose order was fixed before any code (the plan) and tagged v0.2.0 in August, with build provenance attestations on every release artifact. The authorized half followed in sixteen more: the scope tree, the authorization record and its two doors, paths and relationships, versioned definitions, the delta, campaigns rewired, alerts, the read API, the table door, six more providers, the page, Active Directory through two doors, and the populated record a fresh clone gets from one script. A fresh clone with Docker starts the stack, migrates the schema, serves sign-in with three roles behind a tested role matrix, imports identity exports append-only, derives the inventory with its findings, keeps the authorized record beside it, and produces the delta, the campaigns, the risk report, and the escaped exports. The same digest-built image runs on a hardened local Kubernetes cluster: default-deny network policies with three named flows, the restricted pod security standard, an admission policy refusing unpinned images, and workload identities with nothing to steal; every claim has its probe in Running it on Kubernetes. Next is v0.6, the read-only provider connection, in the roadmap; the platform this deploys to is built as code in control-plane.

This is a learning project, built in public, by one person. The software is provided as is under the AGPL 3.0 license. Before relying on any of it, read the code and the threat model, including its accepted risks. Nothing here is production software until the documents say so.