
holos
Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

An SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

Fleet-scale CVE-2026-31431 audit and remediation orchestrator for Linux hosts via SSH, with strict host-key verification and multi-format reporting.

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

DevSec SSH Baseline - InSpec Profile

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

Zero-Trust SSH CA

Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and…

This chef cookbook provides secure ssh-client and ssh-server configurations.

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

This puppet module provides secure ssh-client and ssh-server configurations.

The easiest, and most secure way to access and protect all of your infrastructure.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…