
Go में सेल्फ-होस्टेड SSH एक्सेस गेटवे, जिसमें OIDC/LDAP प्रमाणीकरण, RBAC, MFA, सत्र रिकॉर्डिंग, ऑडिट एक्सपोर्ट, एन्क्रिप्शन एट रेस्ट, IP नियम, और नीति प्रवर्तन शामिल हैं।
GateKeeper एक Go में लिखा गया self-hosted SSH access gateway है।
यह SSH के सामने एक केंद्रीकृत नियंत्रण परत के रूप में कार्य करता है, जो access control, MFA enforcement, session recording, auditing, और policy enforcement प्रदान करता है --- यह सब एक embedded web UI के साथ एक ही binary में।
कोई external control plane नहीं। कोई SaaS dependency नहीं।
GateKeeper पारंपरिक न्यूनतम "bastion host" नहीं है, classic hardened jump-box अर्थ में।
इसके बजाय, यह एक SSH access gateway है जो SSH वातावरणों के लिए authentication, authorization, और auditing को केंद्रीकृत करने के लिए डिज़ाइन किया गया है।
लक्ष्य है नियंत्रित पहुँच और दृश्यता --- न कि zero-service hardened OS मॉडल।
GateKeeper कार्यात्मक है और सक्रिय रूप से परीक्षण किया जा रहा है।
GateKeeper Linux के लिए बनाया गया है। Linux समर्थित production platform है।
Docker, सुसंगत और सुरक्षित deployments के लिए GateKeeper चलाने का अनुशंसित तरीका है।
Windows और macOS builds development के लिए काम कर सकते हैं, लेकिन production deployments को Linux का उपयोग करना चाहिए।
git clone https://github.com/judsenb/gatekeeper.git
cd gatekeeper
make build
./gatekeeper
पहली बार चलाने पर, खोलें:
docker compose up -d
SQLite डिफ़ॉल्ट है। यदि आवश्यक हो तो environment variables के माध्यम से Postgres कॉन्फ़िगर करें।
GateKeeper एक YAML config फ़ाइल का उपयोग करता है जिसमें environment variable overrides होते हैं।
सामान्य environment variables:
यदि TLS फ़ाइलें मौजूद हैं, तो HTTP HTTPS पर redirect करता है। प्रमाणपत्र अपडेट होने पर स्वचालित रूप से reload होते हैं।
make build
make test
make cover
make check
परीक्षण in-memory SQLite का उपयोग करते हैं। CI linting, tests, और vulnerability checks चलाता है।
MIT