
headscale
An open source, self-hosted implementation of the Tailscale control server

An open source, self-hosted implementation of the Tailscale control server

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

Identity-aware proxy providing secure, just-in-time access to hosts with session controls, dynamic credential management, and OIDC integration.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Automating situational awareness for cloud penetration tests.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

A powerful testing tool for Kubernetes clusters.

Security auditing tool for AWS environments

A tool for quickly evaluating IAM permissions in AWS.

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Review Access - kubectl plugin to show an access matrix for k8s server resources