Skip to main content

Product Tour

AlmaForge is a context-driven, self-hosted access plane for engineering teams, automation, and AI agents, replacing permanent credentials and bastions with just-in-time authorization, short-lived certificates, and complete session replay inside your perimeter.

Follow Alice as she resolves incident INC-4821 on prod-web-01 with AlmaForge.

1. Discover Live Infrastructure​

Alice begins by signing in through corporate single sign-on (OIDC). There are zero local user accounts, passwords, or persistent keys to manage.

The live inventory continuously indexes active servers, databases, Kubernetes clusters, and internal applications across clouds and private data centers. Instead of searching stale documentation or guessing hostnames, Alice finds the target server in real time.

almaforge.example.com/resources

Alice finds prod-web-01 in the live resource list. Labels show where each resource runs.

2. Request Just-in-Time Access​

Alice holds zero standing privileges in production. To investigate the incident, she submits a scoped access request through the alma CLI or Web UI:

Terminal
alma request create --roles=prod-ssh --reason="INC-4821" --max-duration=1h

She requests the prod-ssh role for 1 hour, with INC-4821 as the reason. The request explicitly bounds identity, role, duration, and operational justification before access is granted.

almaforge.example.com/requests/new

With no standing access, Alice asks for the prod-ssh role for one hour and names the incident.

3. Context-Driven Approval​

Approvals attach to operational context rather than blanket job titles. Instead of waiting for manual chat pings or relying on rubber-stamp approvals, AlmaForge evaluates real-time state against policy.

Because PagerDuty confirms that Alice is the active on-call engineer for this service, policy automatically approves the request for the requested 1-hour TTL. Approvals can also route to Slack or Telegram when peer review thresholds are required.

almaforge.example.com/requests/4f9c2a71

Alice is on call for the service, so the on-call integration approves her request in seconds.

4. Connect with Native CLI Tools​

Alice never leaves her preferred terminal workflow. She assumes the approved grant and connects to prod-web-01 using standard ssh:

Terminal
alma request assumealma ssh alice@prod-web-01

AlmaForge acts as an identity-aware reverse-tunnel proxy. It issues short-lived, cryptographically signed X.509 and SSH certificates valid strictly for the duration of the grant. No VPN clients to launch, no open inbound firewall ports on the host, and no long-lived keys to rotate.

alice@laptop: ~
$ alma request assume
> Profile URL: https://almaforge.example.com:443
Logged in as: [email protected]
Active requests: 4f9c2a71-3b6e-4d8a-9c1f-7e2d5a0b6c84
Roles: access, prod-ssh
Valid until: 2026-09-24 14:32:00 +0000 UTC [valid for 1h0m0s]
 
$ alma ssh alice@prod-web-01
alice@prod-web-01:~$ systemctl is-active nginx
active
alice@prod-web-01:~$  

Alice gets a one-hour certificate for the role and connects to prod-web-01 with ssh.

5. Terminal Session Replay​

During the session, Alice inspects the service and restarts nginx. Terminal output, timing, and window resizes are captured frame by frame.

Security teams and auditors can review the recorded terminal session in the web player or stream structured audit events into their existing SIEM. Every action is attributed to Alice's verified corporate identity, linked directly to the approved ticket and justification.

almaforge.example.com/recordings/7d1e04b2

Bob opens the recordings and plays Alice's session back, exactly as she typed it.

Next Steps​

Try AlmaForge on your own infrastructure with zero telemetry: