
spire
Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

An open source, self-hosted implementation of the Tailscale control server

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Boundary enables identity-based access management for dynamic infrastructure.

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…