
headscale
An open source, self-hosted implementation of the Tailscale control server

An open source, self-hosted implementation of the Tailscale control server

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

Boundary enables identity-based access management for dynamic infrastructure.

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Review Access - kubectl plugin to show an access matrix for k8s server resources

SSH bastion/jump host/jumpserver

A tool to extract the IdP cert from vCenter backups and log in as Administrator

DSC resources to simplify administration of certificates on a Windows Server.

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

Zero-Trust SSH CA

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

A lightweight, policy-driven framework that brings Zero-Trust micro-segmentation to SOHO networks using WireGuard.

Audit program for AzureAD

PowerShell script to enumerate Azure Active Directory access permissions, including role assignments, service principals, and privileged access…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…