Connected control planes with explicit authority and transport boundaries.
FreeSCIM connects identity intent, Linux authority, infrastructure context, remote operations, observability, and data governance without collapsing their responsibilities.
System model
FreeSCIM is a set of connected control planes, not a monolithic authority. Each plane owns a distinct decision and exchanges bounded evidence with the others.
Sanitized system context for the proven platform.
Architecture boundaries
Federation
SAML and OIDC authenticate humans and establish governed sessions.
Lifecycle
SCIM carries user, group, active-state, and transaction-scoped password intent.
Linux authority
FreeIPA owns directory, Kerberos/POSIX, groups, HBAC, and enforcement.
Infrastructure context
Foreman, Puppet, room inventory, relays, and probes describe the managed estate.
Remote operations
WoL, SSH, VNC, Guacamole, and dedicated jumps act on individual workstations.
Evidence and data
PostgreSQL, living ERD, logs, topology cache, snapshots, and operational memory preserve explainability.
Decision order
Identify the authority and trust path.
Resolve the target identity, host, room, or data object.
Check readiness, health, topology, and policy.
Preview the intended state transition.
Apply through the bounded adapter or helper.
Validate the downstream result and record evidence.