Continuous Auth is a Docker Compose-first platform for continuous authentication using a hybrid User and Entity Behavior Analytics (UEBA) model.
The repository contains end-to-end workflow from authentication-event ingestion through historical feature preparation, hybrid anomaly scoring, risk policy evaluation, analyst review, and optional provider enforcement.
The system is a compact modular monolith with separate runtime processes:
- FastAPI API for ingestion, tenant administration, dashboard reads, and configuration workflows
- Python worker for Redis-backed event processing, feature computation, scoring, alerting, and enforcement jobs
- React + Vite dashboard for analyst and tenant administration workflows
- PostgreSQL as the system of record
- Redis Streams for lightweight asynchronous handoff
- Keycloak as the representative outbound identity-provider integration
Docker Compose is the reference packaging for local development and evaluation. The services use standard containers and environment-based configuration, so the same runtime can be deployed to cloud container infrastructure.
apps/ Runnable API, worker, and dashboard applications
shared/ Domain, schema, persistence, ML, policy, and integration packages
training/ Reproducible model-input and artifact preparation
infra/ Docker, migrations, and deterministic seed data
docs/ Maintained project documentation and review material
Start with docs/context/README.md for the project documentation index.
- Python 3.13 with uv
- Ruff and mypy
- React, Vite, TypeScript, ESLint, and Prettier
- Pre-commit
- Docker Compose
Install the Python workspace:
uv syncBuild and start the complete local stack:
docker compose up -d --buildThe dashboard is available at http://localhost:5173 and the API at http://localhost:8000. Compose applies all Alembic migrations before starting the API and worker, then loads the deterministic seed dataset after the API is healthy. See the seed loader instructions for lifecycle details and manual commands.
Run repository hooks:
pre-commit run --all-filesRun dashboard checks:
npm --prefix apps/dashboard run lint
npm --prefix apps/dashboard run typecheck
npm --prefix apps/dashboard run buildThe core platform implementation and dashboard workflows are complete. Further work should be treated as deliberate feature development or hardening, with architecture changes documented alongside the code.