Bryan Frimin c4e81ed092 Inline OAuth2 signing key in config
The OAuth2/OIDC server accepted its signing key via a file path
(key-file), while every other PEM key in the probod config (SAML
private key, ACME account key) is embedded inline. Switch the
field to a private-key string so the convention is uniform.

The signing key is operator-supplied material that must outlive
any process restart, so the bootstrap builder now treats
OAUTH2_SERVER_SIGNING_KEY as required and refuses to start
without one; silently minting a fresh key per boot would break
token validation across rollouts. The OAUTH2_SERVER_* env vars
otherwise flow through builder.Build like the existing SAML
block so the new OAuth2Server section is populated end-to-end.

Rework the e2e harness to render its config via bootstrap at
test setup, which removes the static
e2e/console/testdata/config.yaml and the previously generated
test-only PEM file. A per-run RSA key is minted via
bootstrap.GenerateOAuth2SigningKey (kept public for test
tooling) and injected through the builder env map. CI now
passes ACME_ROOT_CA inline instead of mutating a YAML on disk.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-04-21 17:56:00 +02:00
2026-04-15 16:42:56 +02:00
2025-04-09 21:19:53 -07:00
2025-11-25 11:29:54 +01:00
2026-04-21 17:56:00 +02:00
2026-04-21 17:56:00 +02:00
2025-12-24 08:46:21 +01:00
2026-04-21 11:38:52 +04:00
2026-03-13 16:55:23 +01:00
2026-04-15 16:42:56 +02:00
2025-01-13 12:56:14 +01:00
2026-04-02 17:58:35 +02:00
2026-04-20 12:11:17 +02:00
2026-04-20 12:11:17 +02:00
2025-04-10 21:04:27 -07:00
2025-01-10 16:31:34 +01:00
2025-12-26 17:33:03 +01:00

Probo - Open Source Compliance

Discord GitHub License GitHub Actions Workflow Status

Probo is an open-source compliance platform built for startups that helps you achieve SOC-2 compliance quickly and efficiently. Unlike traditional solutions, Probo is designed to be accessible, transparent, and community-driven.

🚀 Getting Started

📖 Official Documentation

Prerequisites

  • Go 1.21+
  • Node.js 22+
  • Docker
  • mkcert

Quick Start

  1. Clone the repository:

    git clone --recurse-submodules https://github.com/getprobo/probo.git
    cd probo
    
  2. Install dependencies:

    # Install Go dependencies
    go mod download
    
    # Install Node.js dependencies
    npm ci
    
  3. Start the development environment:

    # Start infrastructure services
    make stack-up
    
    # Build the project
    make build
    
    # Start the application using development settings
    bin/probod -cfg-file cfg/dev.yaml
    

The application will be available at:

Testing Custom Domains

To test the custom domains feature locally, add the CNAME target to your hosts file:

# Add this line to /etc/hosts (macOS/Linux) or C:\Windows\System32\drivers\etc\hosts (Windows)
127.0.0.1 custom.getprobo.com

This allows you to test custom trust center domains on your local machine. The CNAME target can be configured in cfg/dev.yaml under custom-domains.cname-target.

For detailed setup instructions, see our Contributing Guide.

🏗️ Current Status

Probo is in early development, focusing on building a solid foundation for compliance management.

🛠️ Tech Stack

Backend

Frontend

Infrastructure

Observability

  • Grafana - Metrics visualization
  • Prometheus - Metrics collection
  • Loki - Log aggregation
  • Tempo - Distributed tracing

🤝 Contributing

We love contributions from our community! There are many ways to contribute:

  • 🌟 Star the repository to show your support
  • 🐛 Report bugs
  • 💡 Request features
  • 🔧 Submit pull requests
  • 📖 Improve documentation

Please read our Contributing Guide before making a pull request.

📚 Documentation

🌐 Community & Support

📄 License

Probo is MIT licensed.

Description
No description provided
Readme MIT 72 MiB
Languages
Go 67%
TypeScript 31.7%
Shell 0.5%
CSS 0.2%
Makefile 0.2%
Other 0.3%