Open source

Gatehouse

Open source · Just-in-time access control

A self-hosted access request and approval control plane: narrowly scoped, short-lived access, with every decision recorded in a verifiable audit chain.

Gatehouse preview

Problem

With standing production access it's hard to tell who had access, why, and whether policy was followed.

Solution

A just-in-time request and approval workflow with policy context, workspace isolation and a hash-linked audit trail.

Built in

Idempotency keys, optimistic locking and a hash-linked audit chain per workspace. Live demo and public OpenAPI.

Overview

Standing production access creates ambiguity during an incident: who had access, why they needed it, and whether the decision followed policy. Gatehouse answers that with a small, inspectable just-in-time workflow — engineers request narrowly scoped, time-limited access, and approvers review it with the risk and policy context in front of them.

The backend is async FastAPI with Pydantic validation, SQLite locally and PostgreSQL in production. Correctness is handled explicitly: idempotency keys, optimistic locking, policy-bounded TTLs and safe handling of conflicting decisions. Each workspace keeps its own append-only, hash-linked audit chain.

The React + TypeScript review desk runs in live or demo mode and works well from the keyboard. Delivery gets the same care: multi-stage non-root images, health and readiness probes, Kustomize overlays, Terraform, and image releases to GHCR.

What it does

  • Engineers request narrowly scoped, short-lived access
  • Approvers see the risk and policy context before deciding
  • Every decision is written to a workspace-scoped, hash-linked audit chain
  • Workspace isolation with requester, approver and admin roles

What's next

Hiring for a full-stack, Python or AI role — or need something like this built? Let's talk.

I'm available immediately — on-site or hybrid in Moscow, or remote; full-time or contract. I reply within 48 hours — faster on Telegram.

Get in touch TelegramDownload CV

Alhassan Alfarran.

© 2026 · Designed and built by me with Next.js, Tailwind and Framer Motion.

My local time: · Moscow

Notes
How this site is built

Stack

Next.js (App Router) and React, styled with Tailwind CSS and animated with Framer Motion. The contact form sends email through Resend; the site is hosted on Vercel.

Three languages, one layout

English, Russian and Arabic each have their own address (/en, /ru, /ar) and share one set of components. The layout uses logical CSS properties (start/end instead of left/right), so Arabic mirrors right to left without separate styles. The server sends every page with its language and text direction already set, so nothing flips after loading, and the Arabic font is only downloaded when Arabic text is on screen.

Performance and accessibility

Sections below the first screen skip rendering until you scroll near them, and the quick menu loads on first use. Everything works from the keyboard, with a skip link and visible focus, and animations switch off when your system asks for reduced motion.

Source code on GitHub