Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

README.md

AccessFlow — Project Documentation Index

AccessFlow is an open-source database access governance platform. It acts as a full SQL proxy between users and relational databases (PostgreSQL, MySQL), enforcing configurable review and approval workflows before any query reaches live data.

Document Index

File Description
01-overview.md Executive summary, problem statement, goals, non-goals
02-architecture.md System architecture, service descriptions, technology stack
03-data-model.md All database entity schemas with column definitions
04-api-spec.md REST API endpoints, WebSocket events, payload examples
05-backend.md Maven module layout, Spring Boot config, proxy engine, AI analyzer, workflow state machine
06-frontend.md React/Vite project structure, key pages, SQL editor component
07-security.md Auth (JWT + SAML), roles, credential encryption, injection prevention, audit integrity
08-notifications.md Event types, Email/Slack/Webhook config, signed payload schema
09-deployment.md Docker Compose, Helm chart, environment variables reference
11-development.md Repo structure, local setup, testing strategy, coding standards
12-roadmap.md v1.0 → v2.6 milestone scope
13-mcp.md Stateless MCP server, identity-scoped API keys (personal or service-account), exposed tools
14-connectors.md Declarative connector catalog — manifests, install lifecycle, release artifacts
15-engine-sdk.md Engine-plugin SDK — authoring guide for native (non-JDBC) engines, host↔plugin contract, add-an-engine checklist
16-iac.md Infrastructure as Code — Terraform/OpenTofu provider, reusable GitHub/GitLab CI Actions, authenticating pipelines with a service account (UI-issued or declared in bootstrap), registry-publishing runbook
17-api-governance.md API Access Governance — govern outbound REST/SOAP/GraphQL/gRPC calls: connectors, schema ingestion, permissions, masking, dynamic variables
18-deployment-governance.md Deployment Approval Governance — gate CI/CD deployments: pipelines, environments, trigger grants, the fail-closed gate, freeze windows, break-glass, outcome reporting
19-sql-review.md Deterministic SQL Review Rules — the named rule catalog, per-environment OFF / WARN / BLOCK severity, ruleset resolution, the submission chokepoint (BLOCK escalates, never rejects), live editor lint, documented exemptions
20-schema-change-governance.md Schema Change Governance — governed DDL change sets authored once under a deployment pipeline: the "not DML" validation gate and what it admits, deterministic-SQL-review BLOCK refusing the save, freeze-on-promotion, the statements checksum, the statement cap; promotion along the environment ladder — the fail-closed gate, can_ddl with no admin exemption, freeze windows, the request-group execution trigger and the post-apply snapshot; the opt-in schema drift job — baselines, the finding lifecycle, and what drift cannot see
21-aggregate-disclosure.md Aggregate Disclosure Guard (design, #943) — why row caps and masking do not bound what an aggregate query discloses, the minimum-group-size property and where it would be enforced, its explicit non-goals (differencing, totals, extremal aggregates), and the detect-first recommendation for v1
22-service-accounts.md Service Accounts — first-class non-human identities for CI, IaC and AI agents: API-key-only sign-in, choosing a narrow role (and the declarative ADMIN default to override), show-once issuance, graced rotation and revocation, the MCP tool allow-list (and why tools/list still shows every tool), the fail-open per-identity rate limit, on-behalf-of attribution that never widens permissions, declarative-vs-UI ownership and the bootstrap-key re-import trap, a CI runbook

Tech Stack Summary

  • Backend: Java 25 + Spring Boot 4 + Spring Modulith + Spring Security + Flyway + Hibernate 6
  • Frontend: React 19 + Vite + TypeScript + Ant Design 6 + CodeMirror 6
  • Internal DB: PostgreSQL 15+
  • Target DBs: PostgreSQL, MySQL (v1.0)
  • AI Backends: OpenAI API, Anthropic Claude API, Ollama (self-hosted), any OpenAI-compatible endpoint, Hugging Face (Inference Providers router or local TGI) — admin configurable
  • Auth: JWT RS256 + optional SAML 2.0 SSO
  • Deploy: Docker Compose, Helm 3 / Kubernetes
  • Notifications: Email (SMTP), Slack (Incoming Webhooks), Webhooks (HMAC-signed)

License

AccessFlow ships as a single open-source product under the Apache 2.0 license.