This repository has been archived on 2026-04-03. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Jeffrey Smith 1b095d50be
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Successful in 6s
CI/CD / test-go-pg (pull_request) Successful in 2m44s
CI/CD / test-sqlite (pull_request) Successful in 2m50s
CI/CD / build-and-deploy (pull_request) Successful in 1m4s
Feat v0.6.7 native mTLS (#42)
End-to-end mutual TLS without a reverse proxy. Go binary terminates
TLS itself via ListenAndServeTLS. TLS_MODE config (none/server/mtls)
is independent of AUTH_MODE.

- MTLSNativeProvider reads PeerCertificates directly (no header trust)
- Shared helpers extracted to mtls_helpers.go (ParseDN, FingerprintCert)
- MTLSProvider renamed to MTLSProxyProvider for clarity
- BuildPeerTLSConfig for future node-to-node mTLS
- switchboard-ca.sh: CA init, issue-node, issue-user (ECDSA P-256)
- 12 new tests (unit + TLS integration)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-31 18:18:24 +00:00
2026-03-31 12:01:51 +00:00
2026-03-31 18:18:24 +00:00
2026-03-28 22:46:40 +00:00
2026-03-31 18:18:24 +00:00
2026-03-31 18:18:24 +00:00
2026-03-31 17:40:40 +00:00
2026-03-17 22:31:34 +00:00
2026-03-31 18:18:24 +00:00
2026-03-31 12:01:51 +00:00
2026-02-03 21:28:18 +00:00
2026-03-31 12:01:51 +00:00
2026-03-30 11:07:27 +00:00
2026-03-31 18:18:24 +00:00
2026-03-31 18:18:24 +00:00

Switchboard Core

A self-hosted extension platform. Identity, teams, permissions, workflows, and a package system. Everything else ships as installable extensions.

What This Is

Switchboard Core is the kernel. It provides the primitives that extensions build on: users, teams, groups, scoped credentials, a Starlark sandbox, workflow orchestration, notifications, and a package installer. It does not include AI chat, providers, personas, or any domain-specific features — those are all extension packages.

Stack

  • Backend: Go / Gin
  • Frontend: Preact + htm (no build step)
  • Database: PostgreSQL (production) + SQLite (dev/test/edge)
  • Sandbox: Starlark with capability-gated modules
  • Deployment: Single Docker image, Kubernetes

Quick Start

# Docker (recommended)
docker compose up --build
# → http://localhost:3000  (admin/admin)

# Or from source
git clone <repo-url> && cd switchboard-core
cp server/.env.example server/.env  # edit DB credentials
cd server && go run .
# → http://localhost:8080

Bundled packages (workflows, surfaces, task manager) are auto-installed on first boot. See Distribution Guide for production deployment and customization.

Kernel Features

  • Auth: Builtin password, mTLS (client cert), OIDC (Keycloak et al.)
  • Teams & Groups: Horizontal isolation + vertical permissions
  • Packages: Unified registry for surfaces, extensions, libraries, workflows
  • Starlark Sandbox: Capability-gated server-side scripting for extensions
  • Workflows: Staged processes with forms, review, and webhooks
  • Connections: Scoped credential storage (global/team/personal), AES-256-GCM encrypted
  • Notifications: In-app with per-type preferences
  • Audit Log: All admin operations logged
  • Object Storage: PVC or S3-compatible
  • Multi-Replica HA: PG-backed WS tickets and rate limit counters

Documentation

Project Status

v0.5.0 — Realtime pub/sub primitive, dialog audit, and admin permissions UI. Extensions can now publish events to WebSocket channels via Starlark; clients subscribe with sw.realtime.subscribe(). Admin Packages page gains per-permission grant/revoke controls and status badges. See ROADMAP.md for the full journey from v0.1.0 kernel extraction through v0.3.x workflows, v0.4.x Notes surface, to v0.5.x realtime and chat.

License

Proprietary. All rights reserved.

Description
No description provided
Readme Apache-2.0 23 MiB
v0.9.9 Latest
2026-04-03 20:11:58 +00:00
Languages
Go 52.1%
JavaScript 34.6%
CSS 5.5%
Shell 3.8%
HTML 2%
Other 1.9%