Skip to content

Repository files navigation

SessionLayer Control Plane

The control and management plane of SessionLayer, a self-hosted, API-first Zero-Trust SSH access platform used from stock OpenSSH clients. It decides; the Gateway enforces, and the Control Plane never sees SSH session plaintext.

It holds authentication (OIDC, OTP, key pinning, machine identities), authorization (data-plane RBAC, platform RBAC, JIT and break-glass, session limits), the three SSH certificate authorities plus the internal mTLS CA, fleet identity for Gateways and Agents, and the audit and recording metadata stream.

Stack

Spring Boot 4.1 / Java 25, fully reactive (WebFlux + R2DBC on Postgres; Flyway migrates over JDBC at startup). The REST surface is generated from the frozen OpenAPI contract in contracts/; the CP/Gateway/Agent plane is gRPC over mTLS, generated from contracts/proto/.

Build and test

./mvnw -B -ntp verify     # codegen + compile + format/style checks + tests + ITs (needs Docker)
./contracts/lint.sh       # buf lint + buf breaking + redocly OpenAPI lint
java -jar target/controlplane-*.jar

Documentation

Installation, admin guides, the API reference, security model, and runbooks live in the Documentation repository, including the Postgres schema and its migration history in docs/reference/data-model.md. Contract conventions specific to this repo are in contracts/README.md and contracts/VERSIONING.md.

License

GPL-3.0-only. See LICENSE.

About

No description, website, or topics provided.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages