SentientGate is a distributed security platform that sits in front of microservices, observes traffic in real time, detects suspicious behavior, and takes temporary enforcement actions before attacks spread.
Most API security setups fail in one of two ways:
- They are static and rule-only, so they miss evolving attacks.
- They are powerful but expensive, slow, and hard to run privately.
SentientGate is built to solve that gap. It combines fast gateway enforcement with event-driven analysis, historical context, and local AI inference to make security decisions that are both fast and adaptive.
Instead of blocking forever, it applies TTL-based temporary blocks, learns from behavior, and keeps services available under load.
SentientGate is a microservice security fabric with these core capabilities:
- Real-time request filtering at the gateway edge (WebFlux/Reactor)
- Event-driven threat analysis with Kafka
- Behavioral history analysis via gRPC
- Layered detection with strategy-based scoring (Burst, Pattern, Config Paths)
- Dynamic temporary blocking via Redis TTL
- Local LLM anomaly checks using Ollama
- Operational visibility through a React dashboard
SentientGate utilizes an Event-Driven, Out-of-Band Analysis architecture.
- API Gateway checks Redis for active blocks. If allowed, it forwards traffic and asynchronously logs the event to Kafka.
- Logging Service persists logs to PostgreSQL and exposes a rapid gRPC API for history queries.
- MCP Service (Malicious Client Protection) consumes Kafka security events, fetches history via gRPC, and runs rapid synchronous heuristics using isolated Thread Pools.
- AI Service provides deep asynchronous behavioral analysis using local LLMs.
- Detected threats result in immediate TTL-based blocks written back to Redis.
| Service | Purpose | Default Port | Framework |
|---|---|---|---|
ApiGateway |
Entry point, filtering, rate limiting, Redis enforcement | 8079 |
Spring WebFlux |
MCPService |
Security brain, strategy analysis, enforcement decisions | 8080 |
Spring Boot (Isolated Thread Pools) |
AIService |
Local LLM-based anomaly analysis via Ollama | 8082 |
Spring WebFlux |
LoggingService |
Log persistence, gRPC behavior history | 8010 |
Spring Boot + gRPC |
EurekaServer |
Service discovery registry | 8761 |
Spring Cloud Netflix |
Dummy |
Protected downstream test service | 8090 |
Spring Boot |
sentinel-gateway-ui |
Monitoring dashboard | 5173 |
React, Vite |
SentientGate/
├── ApiGateway/
├── MCPService/
├── AIService/
├── LoggingService/
├── EurekaServer/
├── Dummy/
├── UI/sentinel-gateway-ui/
├── k8s/ # Consolidated Kubernetes manifests
├── scripts/ # Automation scripts, per-OS: linux/ + macos/ (Bash), windows/ (PowerShell)
├── TOOLS/ # Local infrastructure docker-compose
├── .github/workflows/ # CI/CD Pipelines
├── ARCHITECTURE.md # In-depth Mermaid diagrams
└── README.md
We provide automation scripts to easily spin up Postgres, Redis, Kafka, and the microservices locally. Use the folder that matches your OS: scripts/linux/ and scripts/macos/ (Bash), or scripts/windows/ (PowerShell). The examples below show Linux; substitute macos or use the PowerShell variant as noted.
./scripts/linux/run_local.sh # macOS: ./scripts/macos/run_local.sh.\scripts\windows\run_local.ps1 # Windows (PowerShell)Note: This script launches the infrastructure and sequentially boots up all microservices.
Execute the full integration test suite across all services:
./scripts/linux/test_local.sh # macOS: ./scripts/macos/test_local.sh.\scripts\windows\test_local.ps1 # Windows (PowerShell)./scripts/linux/stop_local.sh # macOS: ./scripts/macos/stop_local.sh.\scripts\windows\stop_local.ps1 # Windows (PowerShell)SentientGate includes consolidated, production-ready Kubernetes manifests in the k8s/ directory. Instead of fragmented folders, we use consolidated manifest.yml files for each service (e.g., k8s/api-gateway-manifest.yml) containing all necessary ConfigMaps, Deployments, Services, and HPAs.
- Start Minikube:
minikube start- Build and push your Docker images to your registry:
./scripts/linux/build_and_push_images.sh # macOS: ./scripts/macos/build_and_push_images.sh.\scripts\windows\build_and_push_images.ps1 # Windows (PowerShell)- Deploy all services to Kubernetes:
./scripts/linux/deploy.sh # macOS: ./scripts/macos/deploy.sh.\scripts\windows\deploy.ps1 # Windows (PowerShell)SentientGate enforces strict automated testing and quality gates before any changes can be merged into remote main:
-
Pull Request CI (
pr-validation.yml):- Automatically triggers when a Pull Request targeting
mainis opened, reopened, or updated with every subsequent push (synchronize). - Spins up supporting infrastructure (PostgreSQL, Redis, Kafka) and executes the full test suite across all microservices and the UI.
- Automatically cancels outdated runs when newer commits are pushed to the PR branch.
- Automatically triggers when a Pull Request targeting
-
Main Branch CI/CD (
ci-cd.yml):- Triggers on direct pushes or merged pull requests into
main. - Tests run first: Executes the entire test suite.
- Conditional publish: Microservice Docker images are built and pushed to Docker Hub only if and after all tests pass successfully.
- Triggers on direct pushes or merged pull requests into
To prevent unverified changes or direct unreviewed pushes from altering the remote main branch:
- Navigate to your repository on GitHub: Settings > Branches (or Rules > Rulesets).
- Click Add branch protection rule (or create a Ruleset) for branch pattern
main. - Check "Require a pull request before merging".
- Check "Require status checks to pass before merging" and select Run Test Suite.
- Check "Require branches to be up to date before merging".
- Check "Do not allow bypassing the above settings".
Apache 2.0. See LICENSE.

