Open-source, evidence-first security for discovering and analyzing non-human identities across software delivery and workload environments.
Early access: v0.1.0-rc.5. See the implementation and acceptance ledger for verified capabilities and remaining gates. Development builds are not labeled production ready.
flowchart LR
Browser --> Grantline[Go API + React + collection worker]
Grantline --> PostgreSQL[(PostgreSQL)]
Grantline --> Sources[Scoped provider metadata]
Secrets[Private secret files] --> Grantline
SPIRE[SPIRE metadata export] --> Grantline
Kubernetes · Vault · Jenkins · Microsoft Entra · GitHub · SPIRE exports. Supported scope · Permissions · Architecture · Apache-2.0
Mapped to selected OWASP Non-Human Identities Top 10 risks: excessive privileges, credential lifetime and environment isolation. This is not OWASP certification or full NHI coverage.
Download the installation ZIP or TAR package, extract it into a new directory, then run:
docker compose up -d --waitOpen http://127.0.0.1:8080. Read the setup token in your terminal:
docker compose exec app cat /var/lib/grantline/secrets/setup-tokenCreate the first Owner and enroll an authenticator. Invite your team and configure connections through the UI. Go, Node and a source build are not required. The package pins the application image by digest and includes the installation guides.
Prerequisites: Docker with Compose, Linux containers, a free loopback port 8080
and network access to pull the images. Budget 4 vCPU / 8 GB for the reference workload.
Keep generated secret volumes private; do not use down -v to stop a real workspace.
Docker and HTTPS guide · Kubernetes and Helm guide · Product documentation
Container: ghcr.io/grantlinehq/grantline:0.1.0-rc.5 (linux/amd64, linux/arm64).
Helm chart: oci://ghcr.io/grantlinehq/charts/grantline --version 0.1.0-rc.5.
The release page
includes checksums, signatures and the source archive.
To build from a checkout instead:
git clone https://github.com/grantlinehq/grantline.git
cd grantline
docker compose -f compose.yaml -f compose.build.yaml build app
docker compose -f compose.yaml -f compose.build.yaml up -d --waitThese are viewport captures of the running product with synthetic imported evidence. The sample workspace has no live connections; it illustrates the review workflow. Fixture severities are chosen for demonstration and are not universal risk scores.
| Source | Scope |
|---|---|
| Kubernetes | Service accounts, workloads and RBAC metadata |
| Vault | Selected auth roles and policy metadata |
| Jenkins | Selected jobs and pinned Jenkinsfile references |
| Microsoft Entra | Selected applications, service principals and federation |
| GitHub | Selected repositories, workflow revisions and explicit identity mappings |
| SPIRE | Validated metadata exports, SPIFFE identities and registration context |
Provider access remains read-only. The application never needs a Docker socket, privileged container or remotely exposed SPIRE administration socket. Connection credentials are encrypted separately from snapshots and reports. Missing coverage produces explicit uncertainty rather than an assumed clean result.
Grantline collects identity and credential metadata rather than secret payloads. Connector authentication credentials may be stored encrypted or supplied through private files. Operational secret files and plaintext runtime use are separate from report data; read the metadata handling contract.
The workspace includes invited accounts, local passwords and TOTP, OIDC SSO, Owner/Admin/Analyst/Viewer roles, scheduled collection, historical reports, assignment, comments and expiring risk acceptance. Review status is independent of PASS/FAIL/UNKNOWN policy outcomes. Telemetry is not enabled or sent.
The Go application serves React and documentation from one container image. PostgreSQL stores users, encrypted connections, durable jobs and immutable reports; Redis is not required. v0.1 supports one organization and one active application instance. Helm uses a Recreate upgrade with a brief interruption; it does not provide application or database high availability.
- Accounts, MFA and SSO
- Integration preparation
- Configuration
- Backup, restore and key rotation
- Upgrades
- API and CLI
The existing collect, analyze and serve --report CLI workflows are preserved.
The report viewer remains separate from the persistent multi-user server. Synthetic
fixtures and the development design preview are clearly labeled and are not live inventory.
- One organization and one active app instance; no HA or horizontal scaling promise.
- Read-only source analysis, with no automatic provider remediation or universal effective-access calculation. SPIRE uses validated exports.
- Full live-provider/IdP and WCAG acceptance remains open. WSL2 Ubuntu with an independent Docker Engine is tested; standalone Linux, macOS and real ARM64 hardware are not all verified. See the compatibility record.
- Historical imports preserve their age and provenance; missing data is not proof that an identity or finding was resolved.
We welcome pilot users and contributors during early access. Share installation, integration and investigation feedback in Discussions, or use the issue forms for bugs, connector requests and false positives. Include the version and sanitized reproduction steps; keep credentials and private reports out of public posts. Report vulnerabilities through the private channel in SECURITY.
Read CONTRIBUTING, SECURITY, and third-party notices. Product installation files are separate from development labs. Never publish private reports or observer credentials.
Licensed under Apache-2.0. Release operations describe package verification, upgrades and the preview release process.

