RuleGate
RuleGate is an open-source authorization framework I developed to manage role-, permission-, attribute-, resource-, and context-based access rules in .NET and Angular applications through centralized, testable, fail-closed policies.
- Context
- Personal open-source framework project
- Role
- Creator, software architect, and framework developer
- Status
- Completed — stable v1.0.0
- Category
- Framework
- Period
- Jul 26, 2026 - Aug 1, 2026
Technologies
C# .NET Standard 2.0 .NET 8-10 ASP.NET Core Angular 9-22 TypeScript YAML Keycloak OpenTelemetry NuGet npm GitHub Actions xUnit Vitest BenchmarkDotNet
Links
Repository github.com/fotbiler-lab/rulegate Stable Release github.com/fotbiler-lab/rulegate/releases/tag/v1.0.0 Documentation (Wiki) github.com/fotbiler-lab/rulegate/wiki NuGet Package Profile nuget.org/profiles/fotbiler NuGet: Fotbiler.RuleGate.Abstractions nuget.org/packages/Fotbiler.RuleGate.Abstractions NuGet: Fotbiler.RuleGate.Core nuget.org/packages/Fotbiler.RuleGate.Core NuGet: Fotbiler.RuleGate.Manifest nuget.org/packages/Fotbiler.RuleGate.Manifest NuGet: Fotbiler.RuleGate.AspNetCore nuget.org/packages/Fotbiler.RuleGate.AspNetCore NuGet: Fotbiler.RuleGate.Cli nuget.org/packages/Fotbiler.RuleGate.Cli NuGet: Fotbiler.RuleGate.Keycloak nuget.org/packages/Fotbiler.RuleGate.Keycloak npm Package Family npmjs.com/org/fotbiler npm: @fotbiler/rulegate-client npmjs.com/package/@fotbiler/rulegate-client npm: @fotbiler/rulegate-angular npmjs.com/package/@fotbiler/rulegate-angular npm: @fotbiler/rulegate-angular-legacy npmjs.com/package/@fotbiler/rulegate-angular-legacy
Project Type and Current Status
- RuleGate is a local-first, provider-independent, policy-driven authorization framework for .NET and Angular applications.
- The stable v1.0.0 scope was completed and released under the MIT license on 1 August 2026. The source code, documentation, examples, and package publishing definitions are publicly available.
- RuleGate performs authorization, not authentication or user management. It works on top of Keycloak, ASP.NET Core Identity, IdentityServer, or another standards-based identity system.
Problem and Design Goal
- The framework addresses role, claim, permission, and resource checks that often become duplicated across controllers, services, guards, and UI components.
- It centralizes these decisions as readable, deterministic, and testable policies while keeping the protected backend as the security boundary.
- Every decision answers one explicit question: May this subject perform this action on this resource in the current context?
Authorization Model and Capabilities
- The policy model combines RBAC, permission-based authorization, ABAC, CBAC, resource rules, ownership, organization boundaries, and logical all/any/not composition.
- Policies can evaluate subject, resource, and request-context attributes; compare attributes with each other; and apply string, collection, presence, null, time-window, authentication-age, MFA-age, tenant, device, and network-zone rules.
- Policies can be defined in C# or YAML. Typed values, manifest bounds, deterministic evaluation, and explicit missing-data behavior make authorization outcomes predictable.
Package Architecture
- The NuGet family contains six focused packages: Abstractions, Core, Manifest, AspNetCore, Cli, and the optional Keycloak adapter.
- The npm family contains a framework-independent client, a modern Angular package, and a legacy Angular adapter. Browser-side guards and directives improve user experience, but they never replace backend enforcement.
- All six NuGet packages and all three npm packages were published as the coordinated stable 1.0.0 release.
ASP.NET Core, Angular, and Identity Integration
- ASP.NET Core integration supports dynamic policies, Minimal API helpers, MVC attributes, imperative service authorization, trusted attribute enrichment, and safe HTTP result mapping.
- Angular integrations provide guards, directives, authorization-state projection, and generated TypeScript identifiers for both modern and legacy application lines.
- The provider-independent core accepts trusted identity data from the host. The optional Keycloak package normalizes roles and claims without coupling policy definitions to Keycloak.
Policy Lifecycle, CLI, and Observability
- The RuleGate CLI validates, tests, explains, and lints manifests and generates strongly typed C# and TypeScript policy identifiers.
- Policies can be loaded from files, embedded resources, configuration, memory, or application-defined sources and replaced through atomic reload while retaining the last valid snapshot.
- Safe diagnostics and OpenTelemetry activities and metrics provide operational visibility without exposing sensitive authorization attribute values.
Security and Compatibility
- RuleGate uses default-deny and fail-closed behavior. Missing policies, invalid types, absent required data, provider failures, and indeterminate evaluations deny access.
- The stable matrix verifies portable libraries on .NET Standard 2.0 and .NET 8-10, ASP.NET Core integrations from .NET Core 3.1 through .NET 10, and the CLI on .NET 8-10.
- Frontend package consumers cover Angular 9-22 through the framework-independent, modern Angular, and legacy Angular packages. Legacy verification describes compatibility and does not extend vendor security support.
Quality, Testing, and Release Automation
- GitHub Actions validates formatting, builds and tests .NET and Angular packages, audits dependencies, verifies public API freezes, and exercises package-only consumers.
- The quality gates include manifest fuzz and property-based security tests, bounded concurrency stress, benchmarks, generated-code compilation, reference applications, sensitive-diagnostic checks, and reproducible NuGet/npm artifact verification.
- Separate workflows publish signed release artifacts to NuGet and npm, generate release notes, and synchronize the canonical guide with the GitHub Wiki.
Documentation and Reference Applications
- The repository contains a connected fourteen-chapter guide, a glossary, security and compatibility references, migration guidance, real-world recipes, and a generated GitHub Wiki.
- Official reference applications demonstrate a Minimal ASP.NET Core host and a document-approval system using Keycloak, ASP.NET Core, SQLite, Angular, trusted attribute providers, and package-only dependencies.
- The examples keep authentication, authorization, frontend projection, testing, diagnostics, reload, and production responsibilities clearly separated.
Participation and Development Time
- I designed and developed RuleGate independently as its creator, software architect, backend/frontend library developer, test owner, documentation author, and release owner.
- Git history begins on 26 July 2026. The stable v1.0.0 tag was published on 1 August 2026, completing the initial stable scope in seven calendar days when both boundary dates are included.
- I managed the complete path from authorization modeling and public API design to security hardening, compatibility testing, documentation, package automation, and stable publication.
Source Code and Packages
- Source repository: https://github.com/fotbiler-lab/rulegate
- Stable v1.0.0 release: https://github.com/fotbiler-lab/rulegate/releases/tag/v1.0.0
- NuGet package family: https://www.nuget.org/profiles/fotbiler
- npm package family: https://www.npmjs.com/org/fotbiler