awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
openziti avatar

openziti/ziti

0
View on GitHub↗
3,883 estrellas·236 forks·Go·apache-2.0·22 vistasopenziti.io↗

Ziti

Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet.

The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend these security principles to legacy applications without requiring code changes.

The platform covers a broad range of networking and security capabilities, including multi-cloud workload connectivity, network microsegmentation, and private service discovery. It manages traffic through a distributed fabric of routers using dynamic routing based on real-time latency and throughput, all governed by centralized policy orchestration and mutual TLS authentication.

The system supports deployment across various operating systems and cloud providers to establish its distributed architecture.

Features

  • Cryptographic Identity Networks - Provides an identity-based mesh where cryptographic identities replace IP addresses for routing and isolation.
  • Zero Trust Networking - Provides a complete zero-trust networking framework that enforces identity-based access for all network communication.
  • Outbound Connectivity Agents - Eliminates open listening ports by requiring services to initiate outbound connections to the controller.
  • Mesh Networking - Establishes a distributed mesh network of controllers and routers for identity-based service connectivity.
  • Mesh Traffic Optimization - Relays encrypted traffic through a distributed router fabric using real-time latency and throughput optimization.
  • Identity-Based Tunnels - Creates secure network tunnels bound to verified identities instead of IP addresses.
  • Identity-Based Mesh Fabrics - Implements a distributed fabric of controllers and routers for identity-based encrypted traffic routing.
  • Distributed Policy Management - Implements centralized orchestration of network-wide authorization rules and identity certificates.
  • Embedded Networking SDKs - Provides a Zero Trust SDK to embed networking and process-to-process encryption directly into application code.
  • Identity-Embedded Protocols - Embeds cryptographic identities directly into application code to achieve process-to-process end-to-end encryption.
  • Process-Level Encryption - Provides an SDK-based approach for encrypted traffic and identity integration without requiring host-level agents.
  • Mutual TLS Authentication - Requires every network endpoint to prove its identity using mutual TLS authentication before data exchange.
  • Identity-Based Authentication - Coordinates authentication and authorization to ensure every endpoint connection is mutually authenticated.
  • Identity-Based Access Control - Restricts network access to individual applications using cryptographic certificates and identity-based policies.
  • Cryptographic Identity Verification - Issues unique cryptographic certificates to users and devices to ensure strong network authentication.
  • Network Microsegmentation - Restricts access to specific applications using granular identity-based policies to prevent lateral movement.
  • End-to-End Encryption - Applies strong cryptography to all communications to ensure data remains secure from end to end.
  • Embedded Secure Connectivity - Integrates networking and encryption directly into application code via SDKs for end-to-end secure communication.
  • Service Cloaking - Removes listening ports and public URLs by requiring authenticated clients to connect through a secure overlay.
  • Software-Defined Perimeters - Employs a software-defined perimeter to make network services invisible to unauthorized users and scanners.
  • Zero Trust Access - Connects users and devices to applications using cryptographic identities instead of traditional VPNs.
  • Developer SDKs - Ships a Zero Trust SDK for embedding encryption and identity-based access control directly into application code.
  • Service Cloaking - Removes open listening ports and public URLs to make services invisible to unauthorized users and internet scanners.
  • Access Control Policies - Defines granular permissions and policies to restrict which identities can access specific network paths.
  • VPN Alternatives - Provides a connectivity solution that eliminates open listening ports by routing traffic through an authenticated overlay.
  • Legacy Application Tunneling - Provides secure connectivity to legacy applications via lightweight tunnelers without modifying the original code.
  • Multi-Cloud Overlays - Creates a single overlay network across multiple cloud providers and on-premise data centers without using VPN tunnels.
  • Intelligent Routing Engines - Implements an intelligent routing engine to balance security requirements with network performance across a secure overlay fabric.
  • Centralized Management Interfaces - Ships a centralized graphical dashboard and API for controlling and monitoring the network overlay.
  • Traffic Optimization - Directs encrypted traffic through a mesh of routers to optimize paths based on real-time latency, throughput, and cost.
  • Multipath Latency Routing - Uses a mesh fabric that monitors real-time latency across multiple peer links to select the fastest path and provide automatic failover.
  • Overlay Networks - Links diverse workloads across multiple cloud providers and on-premise data centers into a unified private network.
  • Private DNS Resolution - Maps service names to secure overlay tunnels using authenticated private DNS resolution.
  • Transparent Host Security - Extends zero trust principles to existing hosts and applications using a tunneler-based approach without code changes.
  • Private - Maps service names to secure tunnels using private DNS to hide applications from the public internet.
  • Transparent Network Proxies - Implements transparent network proxies that intercept and route traffic for unmodified software.
  • Tunneling Proxies - Ships transparent tunneling proxies to provide secure connectivity to legacy applications without code changes.
  • Zone Access Management - Secures access to applications within trusted network spaces using routers for devices that lack native tunneling capabilities.
  • Network Administration Consoles - Provides a dedicated management interface for administering network identities and connectivity policies.
  • Networking & Connectivity - Zero-trust, programmable network overlay.
  • Overlay Networks - Zero trust overlay network for application-level security.
  • Seguridad y privacidad - Zero-trust, full-mesh overlay network for secure access.
  • Security & Privacy - Zero-trust, full-mesh overlay network for secure connectivity.

Historial de estrellas

Gráfico del historial de estrellas de openziti/zitiGráfico del historial de estrellas de openziti/ziti

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Preguntas frecuentes

¿Qué hace openziti/ziti?

Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet.

¿Cuáles son las características principales de openziti/ziti?

Las características principales de openziti/ziti son: Cryptographic Identity Networks, Zero Trust Networking, Outbound Connectivity Agents, Mesh Networking, Mesh Traffic Optimization, Identity-Based Tunnels, Identity-Based Mesh Fabrics, Distributed Policy Management.

¿Qué alternativas de código abierto existen para openziti/ziti?

Las alternativas de código abierto para openziti/ziti incluyen: tailscale/tailscale — Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted… ockam-network/ockam — Ockam is an end-to-end encryption framework and distributed identity provider designed to establish secure… netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the… build-trust/ockam — Ockam is a zero-trust networking framework designed to secure data transit between distributed applications using an… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… opennhp/opennhp — OpenNHP is a software-defined perimeter controller designed to secure network infrastructure by rendering services…

Alternativas open-source a Ziti

Proyectos open-source similares, clasificados según cuántas características comparten con Ziti.
  • tailscale/tailscaleAvatar de tailscale

    tailscale/tailscale

    32,596Ver en GitHub↗

    Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted mesh network. By utilizing a high-performance, user-space implementation of the WireGuard protocol, it establishes secure peer-to-peer tunnels across diverse network topologies without requiring complex firewall configuration. The platform operates on a centralized control plane that manages global network state, authentication, and policy distribution, ensuring that connectivity is governed by identity rather than traditional IP-based rules. What distinguishes Tailscale is it

    Go2faoauthsso
    Ver en GitHub↗32,596
  • ockam-network/ockamAvatar de ockam-network

    ockam-network/ockam

    4,628Ver en GitHub↗

    Ockam is an end-to-end encryption framework and distributed identity provider designed to establish secure communication between applications and devices. It provides a secure network overlay that utilizes cryptographic identities and attribute-based access control to implement zero trust network access. The project distinguishes itself through metadata-driven multi-hop routing and a pluggable transport layer, allowing encrypted traffic to move across diverse network topologies without requiring virtual IP overlays. It specifically enables secure tunneling for legacy applications by wrapping

    Rust
    Ver en GitHub↗4,628
  • netbirdio/netbirdAvatar de netbirdio

    netbirdio/netbird

    26,188Ver en GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Gogolangmeshmesh-networks
    Ver en GitHub↗26,188
  • build-trust/ockamAvatar de build-trust

    build-trust/ockam

    4,628Ver en GitHub↗

    Ockam is a zero-trust networking framework designed to secure data transit between distributed applications using an identity-based network overlay. It provides the primitives necessary to establish mutually authenticated and end-to-end encrypted connections, removing the reliance on traditional network-layer security. The project is distinguished by its use of attribute-based access control and verifiable credentials to manage trust at scale. It implements cryptographic identity rotation to maintain identity continuity and integrates with hardware-backed key management systems to secure priv

    Rustauthenticationauthorizationcredentials
    Ver en GitHub↗4,628
  • Ver las 30 alternativas a Ziti→