Skip to content

Repository files navigation

SentientGate: AI-Powered Runtime Security for Cloud-Native Microservices

SentientGate is a distributed security platform that sits in front of microservices, observes traffic in real time, detects suspicious behavior, and takes temporary enforcement actions before attacks spread.

The Story

Most API security setups fail in one of two ways:

  1. They are static and rule-only, so they miss evolving attacks.
  2. They are powerful but expensive, slow, and hard to run privately.

SentientGate is built to solve that gap. It combines fast gateway enforcement with event-driven analysis, historical context, and local AI inference to make security decisions that are both fast and adaptive.

Instead of blocking forever, it applies TTL-based temporary blocks, learns from behavior, and keeps services available under load.

What SentientGate Is

SentientGate is a microservice security fabric with these core capabilities:

  • Real-time request filtering at the gateway edge (WebFlux/Reactor)
  • Event-driven threat analysis with Kafka
  • Behavioral history analysis via gRPC
  • Layered detection with strategy-based scoring (Burst, Pattern, Config Paths)
  • Dynamic temporary blocking via Redis TTL
  • Local LLM anomaly checks using Ollama
  • Operational visibility through a React dashboard

Technologies Used

  • Java
  • Spring Boot
  • Apache Kafka
  • Redis
  • PostgreSQL
  • gRPC
  • Ollama
  • React
  • Kubernetes
  • Docker

Architecture & Data Flow

SentientGate Architecture

SentientGate utilizes an Event-Driven, Out-of-Band Analysis architecture.

  1. API Gateway checks Redis for active blocks. If allowed, it forwards traffic and asynchronously logs the event to Kafka.
  2. Logging Service persists logs to PostgreSQL and exposes a rapid gRPC API for history queries.
  3. MCP Service (Malicious Client Protection) consumes Kafka security events, fetches history via gRPC, and runs rapid synchronous heuristics using isolated Thread Pools.
  4. AI Service provides deep asynchronous behavioral analysis using local LLMs.
  5. Detected threats result in immediate TTL-based blocks written back to Redis.

Sequence Flow

SentientGate Sequence Flow

Services

Service Purpose Default Port Framework
ApiGateway Entry point, filtering, rate limiting, Redis enforcement 8079 Spring WebFlux
MCPService Security brain, strategy analysis, enforcement decisions 8080 Spring Boot (Isolated Thread Pools)
AIService Local LLM-based anomaly analysis via Ollama 8082 Spring WebFlux
LoggingService Log persistence, gRPC behavior history 8010 Spring Boot + gRPC
EurekaServer Service discovery registry 8761 Spring Cloud Netflix
Dummy Protected downstream test service 8090 Spring Boot
sentinel-gateway-ui Monitoring dashboard 5173 React, Vite

Repository Structure

SentientGate/
├── ApiGateway/
├── MCPService/
├── AIService/
├── LoggingService/
├── EurekaServer/
├── Dummy/
├── UI/sentinel-gateway-ui/
├── k8s/                     # Consolidated Kubernetes manifests
├── scripts/                 # Automation scripts, per-OS: linux/ + macos/ (Bash), windows/ (PowerShell)
├── TOOLS/                   # Local infrastructure docker-compose
├── .github/workflows/       # CI/CD Pipelines
├── ARCHITECTURE.md          # In-depth Mermaid diagrams
└── README.md

Quick Start (Local Development)

We provide automation scripts to easily spin up Postgres, Redis, Kafka, and the microservices locally. Use the folder that matches your OS: scripts/linux/ and scripts/macos/ (Bash), or scripts/windows/ (PowerShell). The examples below show Linux; substitute macos or use the PowerShell variant as noted.

1. Start Infrastructure & Services

./scripts/linux/run_local.sh          # macOS: ./scripts/macos/run_local.sh
.\scripts\windows\run_local.ps1        # Windows (PowerShell)

Note: This script launches the infrastructure and sequentially boots up all microservices.

2. Run Tests

Execute the full integration test suite across all services:

./scripts/linux/test_local.sh         # macOS: ./scripts/macos/test_local.sh
.\scripts\windows\test_local.ps1       # Windows (PowerShell)

3. Stop Environment

./scripts/linux/stop_local.sh         # macOS: ./scripts/macos/stop_local.sh
.\scripts\windows\stop_local.ps1       # Windows (PowerShell)

Kubernetes Deployment (Production Ready)

SentientGate includes consolidated, production-ready Kubernetes manifests in the k8s/ directory. Instead of fragmented folders, we use consolidated manifest.yml files for each service (e.g., k8s/api-gateway-manifest.yml) containing all necessary ConfigMaps, Deployments, Services, and HPAs.

Deploying to Minikube or any K8s Cluster

  1. Start Minikube:
minikube start
  1. Build and push your Docker images to your registry:
./scripts/linux/build_and_push_images.sh    # macOS: ./scripts/macos/build_and_push_images.sh
.\scripts\windows\build_and_push_images.ps1  # Windows (PowerShell)
  1. Deploy all services to Kubernetes:
./scripts/linux/deploy.sh             # macOS: ./scripts/macos/deploy.sh
.\scripts\windows\deploy.ps1           # Windows (PowerShell)

CI/CD Automation & Quality Gates

SentientGate enforces strict automated testing and quality gates before any changes can be merged into remote main:

  • Pull Request CI (pr-validation.yml):

    • Automatically triggers when a Pull Request targeting main is opened, reopened, or updated with every subsequent push (synchronize).
    • Spins up supporting infrastructure (PostgreSQL, Redis, Kafka) and executes the full test suite across all microservices and the UI.
    • Automatically cancels outdated runs when newer commits are pushed to the PR branch.
  • Main Branch CI/CD (ci-cd.yml):

    • Triggers on direct pushes or merged pull requests into main.
    • Tests run first: Executes the entire test suite.
    • Conditional publish: Microservice Docker images are built and pushed to Docker Hub only if and after all tests pass successfully.

Enforcing Remote Branch Protection (GitHub Settings)

To prevent unverified changes or direct unreviewed pushes from altering the remote main branch:

  1. Navigate to your repository on GitHub: Settings > Branches (or Rules > Rulesets).
  2. Click Add branch protection rule (or create a Ruleset) for branch pattern main.
  3. Check "Require a pull request before merging".
  4. Check "Require status checks to pass before merging" and select Run Test Suite.
  5. Check "Require branches to be up to date before merging".
  6. Check "Do not allow bypassing the above settings".

License

Apache 2.0. See LICENSE.

About

SentientGate is an out-of-band security fabric for microservices. It uses a reactive API gateway and Kafka to asynchronously analyze traffic via strict heuristics and local LLMs. It dynamically applies temporary Redis blocks, ensuring robust threat defense without degrading the critical request path.

Topics

Resources

Code of conduct

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages