Proven end to endIdentity + infrastructureOperator control planeEvidence-led safety

More than middleware: a platform that can prove its outcomes.

FreeSCIM connects SCIM lifecycle and password delivery, SAML and OIDC federation, FreeIPA authority, Foreman and Puppet enrichment, classroom power and remote support, topology, security intelligence, and database operations. Its defining strength is that each path can be observed, explained, and recovered.

Architecture

Designed across authority, network, privilege, and evidence boundaries.

Flask and Python provide the control surface. Gunicorn and systemd operate the runtime. A TLS reverse proxy fronts the application. PostgreSQL stores mappings, snapshots, sessions, topology cache, security events, classroom state, operational memory, and maintenance evidence. Bounded FreeIPA, relay, jump, and database services keep privileged work outside casual browser behavior.

SCIMSAMLOIDCFreeIPAForemanPuppetGuacamolePostgreSQL
FreeSCIM system context across identity, Linux, infrastructure, remote support, evidence, and database control
The complete control-plane context.

What is proven

Capabilities that reach an operational outcome.

01

SCIM and password convergence

User lifecycle, transaction-scoped password delivery, guarded FreeIPA writes, and Linux login proof.

02

SAML and OIDC federation

Protocol readiness, role mapping, sessions, events, security controls, and governed broker capabilities.

03

FreeIPA and Linux authority

Users, groups, HBAC, host groups, Kerberos/POSIX identity, directory health, and enforcement evidence.

04

Foreman and classroom operations

Host and Puppet-fact enrichment, rooms, seats, status, WoL, power, SSH, VNC, and remote support.

05

Topology and observability

Living network graph, detailed logs, SSO and login events, failed attempts, SSH/Guacamole paths, threats, and remediation.

06

Living data control

ERD, schema audit, migration preview and approval, backup, retention, pruning, maintenance, and recovery.

Operational proof

Safety is visible in the UI, runtime, data model, and evidence.

Gates remain after proof. Password writes, remote sessions, power actions, and migrations retain policy and approval boundaries.

Topology is truthful. Configured, inferred, cached, and observed relationships are labeled.

Logs are explanatory. Events include impact, trust, outcome, correlation, and remediation rather than only stack traces.

Recovery is designed. Backups, rollback notes, dry runs, action history, and verification are first-class.

Engineering signal

FreeSCIM is a true platform.

Identity protocols, Linux infrastructure, fleet inventory, network paths, remote support, security intelligence, database governance, operator UX, and transferable documentation meet in one coherent system.