Bastion
Self-hosted access control — auth, MFA, sessions, and audit logs, with zero third-party access to your data.
Dashboard
Overview of your identity infrastructure
Total Users
2,847
+12Active Sessions
143
-8Policies Enforced
24
+2Events (24h)
8,392
+18%Auth Methods
Detailstotal
Active Sessions
Managealice@corp.com
Chrome / macOS · 10.0.1.42
bob@corp.com
Firefox / Linux · 10.0.1.87
carol@corp.com
Safari / iOS · 203.0.113.42
dave@corp.com
Edge / Windows · 10.0.2.15
Access Decisions (24h)
DetailsMFA Enrollment
Configure2,220 enrolled
627 not enrolled
+5.2% this week
WhatBastiondoes.
Securebydefault.
Howeverychangeships.
Continuous Integration
Linting, tests, scans, and builds gate every commit — producing a signed, hardened image only when everything passes.
Learn more →Continuous Deployment / GitOps
Merging main updates Kustomize overlays via bot PR. ArgoCD reconciles the cluster automatically — no manual apply.
Learn more →Boot Sequence
Init containers enforce startup order: DB check, migrations, then services — ensuring zero boots on unready databases.
Learn more →Theriskengine.
Model Retraining
A daily CronJob retrains on recent activity and hot-swaps the model — no restart needed.
Learn more →Risk Evaluation
Every request is scored on login history, action, and timing. High risk triggers step-up auth.
Learn more →Resilient Fallback
If scoring fails, auth doesn't stop — it defaults to a neutral score and keeps running.
Learn more →Zerotrust,bydesign.
One Policy, Everywhere
The same deny-first rule governing user access governs service-to-service traffic too.
Least Privilege
Workloads get scoped to exactly what their job requires — nothing assumed.
Trust Never Expires
Sessions are re-verified continuously, across every device.
TryBastionnow.
The project's open and ready for contributors — dig into the code or open an issue anytime.
View on GitHub