awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
openziti avatar

openziti/zrok

0
View on GitHub↗
4,477 estrellas·206 forks·Go·Apache-2.0·15 vistaszrok.io↗

Zrok

zrok es un servicio de redes de confianza cero (zero trust) que proporciona una malla superpuesta segura para exponer servicios y archivos locales a través de firewalls y NAT, sin necesidad de redireccionamiento manual de puertos. Funciona como un gestor de redes de confianza cero, orquestando identidades, políticas y enrutadores para establecer conectividad segura entre aplicaciones y usuarios.

El proyecto se distingue por el uso de enrutamiento basado en identidad y frontends HTTP reforzados que se integran con proveedores de identidad externos. Estas capacidades permiten la creación de proxies conscientes de la identidad y proxies inversos seguros que autentican a los usuarios antes de otorgar acceso a aplicaciones web internas.

Las capacidades más amplias de la plataforma incluyen el intercambio de recursos peer-to-peer para servicios TCP y UDP, el uso compartido de unidades de red y la microsegmentación consciente de la identidad para redes de TI y tecnología operativa. También proporciona una interfaz programable mediante un SDK de intercambio seguro para integrar estas capacidades de túnel directamente en aplicaciones externas.

La infraestructura puede desplegarse como un controlador autohospedado y una pila de red privada en entornos Linux, Docker o Kubernetes.

Features

  • Mesh Networking - Creates a secure overlay mesh network to connect peers without requiring firewall port forwarding.
  • Zero Trust Networking - Provides a secure overlay mesh for identity-based network communication that bypasses firewalls and NAT.
  • Infrastructure Orchestration - Provides a centralized platform for orchestrating identities, policies, and routers across the network.
  • Reverse Proxies with Integrated Security - Implements a hardened reverse proxy that enforces identity-based authentication before routing traffic to internal services.
  • Local Resource Exposure - Exposes local web applications to the public internet via secure encrypted tunnels without manual port forwarding.
  • Peer-to-Peer Tunneling - Establishes secure peer-to-peer connections for services and files without opening firewall ports.
  • Secure Local Service Exposure - Exposes local web applications or files to the internet through firewalls and NAT without manual port forwarding.
  • Centralized Security Agents - Uses a centralized management plane to push security policies to distributed agents that enforce connectivity.
  • Encrypted Tunneling - Encapsulates data within secure tunnels to bypass NAT and firewalls with end-to-end encryption.
  • Identity-Aware Proxies - Provides a gateway that verifies user identity through external providers to secure internal web applications.
  • Cryptographic Identity Networks - Directs network traffic based on cryptographically verified user identities instead of IP addresses.
  • Identity-Aware Web Gateways - Provides a secure entry point for web services that authenticates users via an external identity provider.
  • Orchestration Consoles - Provides a centralized console for orchestrating zero-trust identities, policies, and network routers.
  • Private Infrastructure Hosting - Supports deploying and managing a complete zero-trust networking stack on self-hosted or air-gapped hardware.
  • Self-Hosted Deployments - Provides automated installation for the controller, frontend, and data stores on private Linux servers.
  • Zero Trust Infrastructure Deployment - Supports installation and management of zero-trust infrastructure across Linux, Docker, and Kubernetes.
  • Network Drive Sharing - Turns local folders into shareable network drives accessible to remote users.
  • Network Stacks - Enables the deployment of a complete zero-trust networking stack within on-premises or air-gapped environments.
  • Network Tunneling Tools - Provides a utility for creating secure tunnels to expose local services to remote clients.
  • Secure Tunneling SDKs - Provides a secure sharing SDK for embedding tunneling capabilities directly into external applications.
  • External Identity Provider Integration - Requires users to verify their identity via external providers before accessing services through HTTP frontends.
  • External Resource Sharing - Provides secure connection methods for TCP and UDP services between specific users without public exposure.
  • Identity Provider Integrations - Hardens service entry points by delegating user verification to external identity providers.
  • Authenticated HTTP Gateways - Implements secure gateways that authenticate users via identity providers for browser-based access to HTTP services.
  • Micro-Segmentation Techniques - Enforces identity-aware security policies and observes traffic flows across IT and OT networks.
  • OT - Deploys firewall agents in operational technology environments to enforce identity-based security policies.
  • Embedded Zero Trust SDKs - Provides a secure sharing SDK to embed zero-trust tunneling capabilities directly into external applications.
  • Tunneling and Proxying - Effortless sharing for both public and private endpoints.

Historial de estrellas

Gráfico del historial de estrellas de openziti/zrokGráfico del historial de estrellas de openziti/zrok

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Preguntas frecuentes

¿Qué hace openziti/zrok?

zrok es un servicio de redes de confianza cero (zero trust) que proporciona una malla superpuesta segura para exponer servicios y archivos locales a través de firewalls y NAT, sin necesidad de redireccionamiento manual de puertos. Funciona como un gestor de redes de confianza cero, orquestando identidades, políticas y enrutadores para establecer conectividad segura entre aplicaciones y usuarios.

¿Cuáles son las características principales de openziti/zrok?

Las características principales de openziti/zrok son: Mesh Networking, Zero Trust Networking, Infrastructure Orchestration, Reverse Proxies with Integrated Security, Local Resource Exposure, Peer-to-Peer Tunneling, Secure Local Service Exposure, Centralized Security Agents.

¿Qué alternativas de código abierto existen para openziti/zrok?

Las alternativas de código abierto para openziti/zrok incluyen: netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the… firezone/firezone — Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to… fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… openziti/ziti — Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… build-trust/ockam — Ockam is a zero-trust networking framework designed to secure data transit between distributed applications using an…

Alternativas open-source a Zrok

Proyectos open-source similares, clasificados según cuántas características comparten con Zrok.
  • netbirdio/netbirdAvatar de netbirdio

    netbirdio/netbird

    26,188Ver en GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Gogolangmeshmesh-networks
    Ver en GitHub↗26,188
  • firezone/firezoneAvatar de firezone

    firezone/firezone

    8,701Ver en GitHub↗

    Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to internal network resources. It functions as a virtual private network that synchronizes authentication and user groups via OpenID Connect providers. The system implements a group-based access control engine to enforce least privilege by restricting network resources to specific user groups. It utilizes holepunching and relay protocols for NAT traversal to establish encrypted tunnels through firewalls without requiring inbound ports. The platform includes a control plane for managing

    Elixirclouddevsecopselixir
    Ver en GitHub↗8,701
  • fosrl/pangolinAvatar de fosrl

    fosrl/pangolin

    21,255Ver en GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    Ver en GitHub↗21,255
  • openziti/zitiAvatar de openziti

    openziti/ziti

    3,883Ver en GitHub↗

    Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend

    Goappsecgolangmesh
    Ver en GitHub↗3,883
Ver las 30 alternativas a Zrok→