A secure, role-based HTTP Request Management and Execution platform built with Next.js.
758
Heimdall is a secure, role-based HTTP Request Management and Execution platform built with Next.js 16. It acts as an intermediate approval layer for sensitive internal API requests, requiring designated approvers to vet payloads before they are physically executed on the backend network.
AUTH_MODE toggle.REQUESTER or APPROVER dynamically via whitelist environment constraints.stdout across all endpoint lifecycles—making Heimdall instantly plug-and-play with scraping infrastructures like Datadog, ELK, or Loki.performance.now() are permanently attached to the ticket for post-mortem inspection.ldap-authentication for Active Directory and vanilla fetch() + jose for pure natively validated OAuth2 (OIDC) JSON Web Tokens.Install Dependencies
npm install
Configure Environment
Copy .env.example to .env (or create a .env file natively) and populate your database architecture alongside your AD/LDAP variables:
# Database Configuration
DATABASE_URL="file:./dev.db"
# Flexible Environment Toggles
AUTH_MODE="LDAP" # Choose strictly "LDAP" or "SSO"
# LDAP / Authentication Configuration
MOCK_LDAP="true" # Set to false to bind to real LDAP instances
LDAP_URL="ldap://your-server:389"
LDAP_SEARCH_FILTER="(|(sAMAccountName=%s)(userPrincipalName=%s))"
# OIDC Configuration (If AUTH_MODE="SSO")
OAUTH_CLIENT_ID="your-client-id"
OAUTH_CLIENT_SECRET="your-client-secret"
OAUTH_AUTH_URL="https://accounts.google.com/o/oauth2/v2/auth"
OAUTH_TOKEN_URL="https://oauth2.googleapis.com/token"
OAUTH_REDIRECT_URI="http://localhost:3000/api/auth/callback"
# Security Roles
APPROVERS="admin,supervisor.name"
Sync Database Architecture
npx prisma db push
Launch Application
npm run dev
The repository contains a fully structured Dockerfile to seamlessly host the server on any infrastructure without local dependencies.
Build the container natively:
docker build -t heimdall-platform .
Run the secure instance:
docker run -p 3000:3000 --env-file .env -d heimdall-platform
FORCE_HTTPS=true is set, development setups natively bypass the "Secure" flag on cookies allowing local infrastructure hosting across IP networks.next.config.ts dynamically scans node hardware IP paths internally to allow hot-reloading anywhere on the VM array natively.Content type
Image
Digest
sha256:8de6c87d5…
Size
278.4 MB
Last updated
6 months ago
docker pull lerufic/heimdall