This repository has been archived on 2026-04-03. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Jeffrey Smith b10f5bee05
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Successful in 5s
CI/CD / test-go-pg (pull_request) Successful in 2m22s
CI/CD / test-sqlite (pull_request) Successful in 2m35s
CI/CD / build-and-deploy (pull_request) Successful in 1m18s
drop users.role column: full RBAC through group membership
The role column was a pre-RBAC artifact. All authorization now flows
through explicit group membership and permission grants:

- Everyone group: all users added on creation (no implicit membership)
- Admins group: grants surface.admin.access + all platform permissions
- JWT claims, login response, profile: role field removed
- OIDC: isIdPAdmin() maps IdP claims → Admins group (no role writes)
- Admin UI: role dropdown removed, admin managed through groups
- Middleware cache simplified to isActive only

28 files changed, -79 lines net. Zero magic roles.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 17:23:12 +00:00
2026-03-17 22:31:34 +00:00
2026-02-03 21:28:18 +00:00

Switchboard Core

A self-hosted extension platform. Identity, teams, permissions, workflows, and a package system. Everything else ships as installable extensions.

What This Is

Switchboard Core is the kernel. It provides the primitives that extensions build on: users, teams, groups, scoped credentials, a Starlark sandbox, workflow orchestration, notifications, and a package installer. It does not include AI chat, providers, personas, or any domain-specific features — those are all extension packages.

Stack

  • Backend: Go / Gin
  • Frontend: Preact + htm (no build step)
  • Database: PostgreSQL (production) + SQLite (dev/test/edge)
  • Sandbox: Starlark with capability-gated modules
  • Deployment: Single Docker image, Kubernetes

Quick Start

git clone <repo-url> && cd switchboard-core
cp server/.env.example server/.env  # edit DB credentials
cd server && go run .
# → http://localhost:8080

Kernel Features

  • Auth: Builtin password, mTLS (client cert), OIDC (Keycloak et al.)
  • Teams & Groups: Horizontal isolation + vertical permissions
  • Packages: Unified registry for surfaces, extensions, libraries, workflows
  • Starlark Sandbox: Capability-gated server-side scripting for extensions
  • Workflows: Staged processes with forms, review, and webhooks
  • Connections: Scoped credential storage (global/team/personal), AES-256-GCM encrypted
  • Notifications: In-app with per-type preferences
  • Audit Log: All admin operations logged
  • Object Storage: PVC or S3-compatible
  • Multi-Replica HA: PG-backed WS tickets and rate limit counters

Documentation

Project Status

v0.1.0 (in progress) — kernel extracted from chat-switchboard v0.38.5. ~44K lines of chat/AI code removed, 27 kernel tables, 20 store interfaces. See ROADMAP.md for details.

License

Proprietary. All rights reserved.

Description
No description provided
Readme Apache-2.0 23 MiB
v0.9.9 Latest
2026-04-03 20:11:58 +00:00
Languages
Go 52.1%
JavaScript 34.6%
CSS 5.5%
Shell 3.8%
HTML 2%
Other 1.9%