Air-gapped IT Service Management AGPL-3.0 Open Source

Introducing RAIN

Response to Asynchronous Interactions in Networks. A self-hosted, sovereign IT system of record designed specifically for air-gapped and controlled operational environments.

Motivation

πŸ”’ Sovereign, Offline Operation

Enterprise ITSM tools require cloud licensing servers, external telemetry, and heavy JavaScript chains. Critical infrastructure and classified/air-gapped networks need a lightweight, self-hosted system that operates reliably with zero internet dependency.

⚑ Operational Evidence Engine

Compliance auditors evaluate operational artifactsβ€”not policy declarations. RAIN functions as an automated evidence engine, turning live events, change flows, and asset changes into verifiable audit trails.

🌐 Asynchronous Event Bus

Networks produce telemetry asynchronously across disconnected segments. RAIN ingests raw Syslog feeds, buffers network signals, and automatically promotes critical signals into structured tickets.

πŸ› οΈ Zero-Build Toolchain Design

Built with Python, FastAPI, Jinja2, and vanilla CSS/JS. Simple maintenance without a garland of dependencies, complex compilation steps, or security supply chain risks.

Core Capabilities

Asset Tracker

Flexible asset management focused on direct inventory control rather than rigid CMDB methodologies.

  • Custom dynamic schema & attributes
  • CSV, JSON, and Excel import/export
  • Direct association with tickets & events
  • Multi-tenant asset isolation
Unified Ticketing

Centralized lifecycle management for operational requests, security events, and system changes.

  • Incident, vulnerability, change requests
  • Rule-based automated event promotion
  • Multi-tenant approval flows
  • Client portal with optional public portal
Syslog Ingestion Engine

Native integration with security tools to bridge event detection directly to operational response.

  • BYO dicovery, IaC, SIEM, XDR, APM, and many other products
  • Regex and pattern matching event rules
  • Automated severity classification
  • Python River based ML rules for anomaly detection
Calendar

Integrated operational scheduling for maintenance windows and routine procedures.

  • Recurring maintenance event tracking
  • Syslog event correlation with maintenance
  • Tenant-scoped calendar visibility
  • "Events happening today" client portal widget
Document Repository

Built-in knowledge management and document archive for SOPs and compliance documentation.

  • Local or S3-compatible storage backend
  • Automatic daily document refresh from external feeds
  • Ticket attachments and evidentiary links
Audit and Change Control

Built for strict control framework requirements and regulatory environments.

  • Immutable system action logging
  • Customizeable group approvals for action
  • Role-Based Access Control (RBAC) with local, SAML, and LDAP auth
  • In-line evidence generation capabilities

Resources

πŸ“– Architectural Overview

System design, technical stack decisions, deployment shapes, and production considerations.

architecture.md β†’

πŸ“Š NIST 800-53 Controls Mapping

In-depth analysis of FedRAMP High, ISO 27001, PCI-DSS v4.0, and international framework compliance.

itsm-controls-mapping.md β†’

πŸ› οΈ User and Admin Guide

Task-oriented workflows for managing tenants, asset fields, event rules, and notifications.

user-guide.md β†’

πŸš€ Quickstart

Main codebase, Docker Compose configurations, Helm charts, and quickstart instructions - including one command "try me now" image.

README.md β†’

Preview

RAIN Platform User Interface Screenshot

Global Framework Alignment

Designed to generate operational evidence artifacts across major global security baselines:

FedRAMP High / Moderate NIST SP 800-53 ISO/IEC 27001:2022 PCI-DSS v4.0 SOX ITGC BSI IT-Grundschutz ANSSI SecNumCloud MAS TRM ITSG-33 / PBMM ACSC Essential Eight