Gatehouse
Open source · Just-in-time access control
A self-hosted access request and approval control plane: narrowly scoped, short-lived access, with every decision recorded in a verifiable audit chain.

Problem
With standing production access it's hard to tell who had access, why, and whether policy was followed.
Solution
A just-in-time request and approval workflow with policy context, workspace isolation and a hash-linked audit trail.
Built in
Idempotency keys, optimistic locking and a hash-linked audit chain per workspace. Live demo and public OpenAPI.
Overview
Standing production access creates ambiguity during an incident: who had access, why they needed it, and whether the decision followed policy. Gatehouse answers that with a small, inspectable just-in-time workflow — engineers request narrowly scoped, time-limited access, and approvers review it with the risk and policy context in front of them.
The backend is async FastAPI with Pydantic validation, SQLite locally and PostgreSQL in production. Correctness is handled explicitly: idempotency keys, optimistic locking, policy-bounded TTLs and safe handling of conflicting decisions. Each workspace keeps its own append-only, hash-linked audit chain.
The React + TypeScript review desk runs in live or demo mode and works well from the keyboard. Delivery gets the same care: multi-stage non-root images, health and readiness probes, Kustomize overlays, Terraform, and image releases to GHCR.
What it does
- Engineers request narrowly scoped, short-lived access
- Approvers see the risk and policy context before deciding
- Every decision is written to a workspace-scoped, hash-linked audit chain
- Workspace isolation with requester, approver and admin roles
What's next
Hiring for a full-stack, Python or AI role — or need something like this built? Let's talk.
I'm available immediately — on-site or hybrid in Moscow, or remote; full-time or contract. I reply within 48 hours — faster on Telegram.