Self-hosted scheduling and lead routing for teams that need control.
Enterprise SSO · feature-level RBAC · PostgreSQL · grounded AI · AWS and Azure infrastructure as code
Scheduling looks simple until teams have to balance availability, ownership, routing rules, and a growing volume of meetings. ConseilTek built Openslot to bring those decisions into one clear workspace. Teams can publish booking types, route leads fairly, prevent double-booking at the database layer, and ask grounded operational questions without handing control to a hosted scheduling vendor.
This repository is a working implementation, not a UI mockup. It includes the application, transactional APIs, PostgreSQL migrations, enterprise identity configuration, automated tests, container packaging, and validated infrastructure definitions for both AWS and Azure.
- Working Next.js 15 application with responsive ConseilTek visual design
- Booking dashboard, route-pool visibility, utilization analytics, copyable booking links, and create-booking interaction
- Conflict-safe PostgreSQL 16 model using an exclusion constraint on host time ranges
- Feature-level RBAC enforced in both navigation and server-side API routes
- Generic OIDC login for Okta and Microsoft Entra ID; SAML providers such as Duo can connect through Keycloak or another broker
- AI routing copilot with local grounded retrieval and optional OpenAI Responses API
file_search - Redis-backed distributed assistant rate limiting with a safe local fallback
- Audit events, health/readiness checks, validation, database migrations, and realistic seed data
- Local Docker Compose stack with PostgreSQL, Redis, and a preconfigured Keycloak realm
- AWS App Runner + Aurora PostgreSQL Serverless v2 + ElastiCache Serverless Terraform
- Azure App Service Web App for Containers + PostgreSQL Flexible Server + Azure Managed Redis Bicep
Requirements: Docker with Compose v2, or Node.js 22+ and pnpm 11 for manual development.
cp .env.example .env
docker compose up --buildOpen http://localhost:3000. The local Keycloak realm is available at http://localhost:8080. The realm import and demo credentials are documented in Authentication.
For a fast UI-only tour, keep AUTH_DEMO_MODE=true and use one of the visible demo personas. Demo mode is forcibly off in production unless it is deliberately re-enabled.
pnpm install
pnpm db:migrate
pnpm db:seed
pnpm devThe service checks configuration at runtime. PostgreSQL is the system of record; Redis improves distributed rate limiting but does not hold durable business records.
This repository intentionally does not recommend static-web hosting. Openslot has authenticated server routes, database transactions, SSO callbacks, and AI orchestration. It belongs on a managed application runtime:
| Cloud | Web compute | PostgreSQL | Cache | Infrastructure |
|---|---|---|---|---|
| AWS | AWS App Runner | Aurora PostgreSQL Serverless v2 | ElastiCache Serverless | Terraform guide |
| Azure | Azure App Service Web App for Containers | PostgreSQL Flexible Server | Azure Managed Redis | Bicep guide |
These managed services reduce operational maintenance by handling web-runtime availability, TLS integration, scaling, database backups, patching, and cache operations. Private S3/Blob storage is used only for application artifacts—not to host the web app.
- Architecture and request flow
- Authentication: Okta, Entra ID, Duo, OIDC, and SAML
- Role-based access control
- AI and RAG configuration
- Security model
- Operations and release readiness
pnpm check
terraform -chdir=infra/aws validate
bicep build infra/azure/main.bicep
docker build -t openslot:local .CI repeats linting, static type analysis, tests, the production build, container build, Terraform validation, and Bicep compilation.
src/app/ pages and authenticated API routes
src/components/ application shell, dashboards, AI, access UI
src/config/ product and RBAC policy configuration
src/lib/ authorization, database, retrieval, rate limits
db/migrations/ versioned PostgreSQL schema
knowledge/ approved documents for optional RAG ingestion
deploy/keycloak/ local identity-broker realm
infra/aws/ App Runner architecture in Terraform
infra/azure/ App Service architecture in Bicep
docs/architecture/ editable SVG architecture diagrams
Apache 2.0. See LICENSE. The ConseilTek trademarks and supplied brand artwork remain the property of ConseilTek; the source code is licensed independently.
Openslot is designed, built, and maintained by ConseilTek. It is published through the ConseilTek Tektons organization as part of our open engineering portfolio. Questions, responsible security reports, and partnership inquiries can be sent to support@conseiltek.com.