GraceSolutions 2376daf91c feat(startup): wire runner, engine, and scheduler into foreground mode
Derives a 32-byte AES key from the configured secret via SHA-256, constructs
the ConnectionService, Runner, and Engine, and starts the Scheduler so
enabled rules fire automatically. Injects the shared services into the HTTP
server via a new Dependencies struct so API handlers can reuse them.
2026-04-23 12:14:50 -04:00
2026-04-15 14:51:53 -04:00
2026-04-15 14:23:32 -04:00
2026-04-15 14:23:32 -04:00

OrchestrAD

OrchestrAD is a modern, rule-based automation platform for Active Directory. It enables dynamic group membership, object lifecycle orchestration, and policy-driven directory operations through a clean UI, REST API, and powerful scheduling engine.


🚀 Overview

OrchestrAD replaces static scripts and JSON-based tooling with a centralized, database-backed system for managing directory automation.

It allows administrators to define rules that evaluate Users, Computers, and Groups, then automatically perform actions such as:

  • Adding/removing group memberships
  • Moving objects to Organizational Units (OUs)
  • Creating groups dynamically
  • Nesting groups
  • Enforcing directory structure and policy consistency

All configuration is managed through the UI or API — no manual file editing required.


Key Features

🔁 Rule-Based Automation

  • Visual rule builder with condition groups and logical operators
  • Supports multiple object types (Users, Computers, Groups)
  • Rich condition support (equals, regex, LDAP, comparisons, etc.)
  • Multiple actions per rule with ordered execution

🧠 Dynamic Directory Orchestration

  • Add/remove group membership with diff-based execution
  • Move objects to OUs with dynamic path generation
  • Auto-create groups and OUs when missing
  • Support for nested group relationships

⏱️ Scheduling Engine

  • Easy schedules (e.g., every 5 minutes)
  • Advanced 6-field cron expressions
  • Per-rule execution control and concurrency handling

🔐 Secure Authentication & Access

  • Local authentication (Argon2-secured)
  • OIDC support (via NextAuth/Auth.js)
  • API key system (separate from user auth)
  • Role-based access control (RBAC)

🔑 Credential Management

  • Reusable, encrypted credential objects
  • Secure storage using AEAD encryption
  • Credential testing and validation

📊 Observability & Auditing

  • Centralized logging with rotation and retention
  • Human-readable logs with structured context
  • Full audit trail for all actions and changes
  • Rule execution history and summaries

💾 Backup & Restore

  • Automatic database backups with retention
  • Manual backup and restore support
  • Safe restore with validation and rollback protection

📦 Cross-Platform Runtime

  • Single Go binary

  • Runs as:

    • foreground process
    • system service
    • Docker container
  • Supports Windows, macOS, and Linux (amd64 + arm64)


🧱 Architecture

  • Backend: Go (Chi, sqlc, SQLite, robfig/cron)
  • Frontend: Next.js + Material UI + Tailwind (Spike Template)
  • Database: SQLite (WAL mode, migrations enabled)
  • Auth: NextAuth/Auth.js (UI sessions) + backend RBAC/API keys
  • Directory Integration: LDAP/LDAPS via go-ldap

🔐 Authentication Model

OrchestrAD separates authentication concerns:

  • Browser Sessions

    • Managed via NextAuth/Auth.js
    • Supports OIDC and local login
  • API Access

    • Managed via API keys
    • Keys can expire or persist indefinitely
    • Shown only once at creation
  • Backend Authorization

    • All security decisions enforced server-side
    • RBAC controls access to resources and actions

🧾 Logging Format

Standard logs:

[TimestampUTC] - [Component] - [Level] - Message

Error logs:

[TimestampUTC] - [Component] - [Level] - [File:Line:Column] - Message

Logs are designed to be:

  • Clear and human-readable
  • Operationally useful
  • Free of unnecessary noise

⚙️ Configuration

Configuration is managed via:

  • Environment variables
  • Secure secrets
  • Database-backed runtime configuration

Supports:

  • Export and import of configuration (JSON)
  • Schema versioning
  • Credential portability with key validation

📦 Build & Versioning

  • Version format: yyyy.MM.dd.HHmm

  • Multi-platform builds:

    • Windows (amd64, arm64)
    • macOS (amd64, arm64)
    • Linux (amd64, arm64)

Output structure:

/binaries
  /windows
  /macos
  /linux

Windows builds embed application icon from /resources/icons.


🐳 Docker

OrchestrAD supports containerized deployment:

  • Runs in foreground mode by default

  • Supports bind mounts for:

    • database
    • logs
    • backups
  • Health endpoints available for orchestration


📌 Use Cases

  • Dynamic group membership automation
  • Directory cleanup and normalization
  • Organizational policy enforcement
  • Zero-touch user and device placement
  • Identity lifecycle orchestration

S
Description
OrchestrAD is a rule-driven Active Directory automation platform that enables dynamic group management, object orchestration, and policy-based directory operations through a modern UI, API, and scheduling engine.
Readme GPL-3.0 101 MiB
2026-09-04 01:06:19 +00:00
Languages
Go 57.6%
TypeScript 40.1%
MDX 1.4%
PowerShell 0.6%
Dockerfile 0.3%