
spire
Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

A tool to scan Kubernetes cluster for risky permissions

Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

Java client providing fluent DSL access to Kubernetes and OpenShift REST APIs for managing cloud-native infrastructure, pods, services, and…

Review Access - kubectl plugin to show an access matrix for k8s server resources

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

Provides open-source SSO and identity provider functionality with SAML, OAuth2/OIDC, LDAP, and RADIUS support for centralized authentication,…

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Pull Request-like Review/Approval flow for database queries. For compliant but smooth Engineering access to production.

Proof-of-concept exploit for CVE-2020-1764 authentication bypass in Kiali 0.4.0–1.15.0, enabling unauthorized API access via crafted JWT tokens.

The Secure CommsOS™ for mission-critical operations

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

OpenID Certified OAuth 2.0 and OpenID Connect provider for token issuance, client management, JWKS, and login/consent flow orchestration via headless…