awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
gravitational avatar

gravitational/teleport

0
View on GitHub↗
19,863 stars·1,993 forks·Go·agpl-3.0·40 viewsgoteleport.com↗

Teleport

Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers, databases, and Kubernetes clusters. It functions as a centralized gateway that replaces static credentials with short-lived, identity-bound cryptographic certificates, effectively eliminating the need for traditional VPNs and long-term secret exposure.

The platform distinguishes itself by orchestrating access through a unified control plane that maps external identity provider claims to granular, role-based infrastructure permissions. It enforces security through mutual TLS gateways and identity-aware proxies, ensuring that every interaction is authenticated, authorized, and recorded. By automating the lifecycle of ephemeral credentials and providing comprehensive session recording, it enables organizations to maintain a searchable audit trail across heterogeneous, multi-cloud, and on-premises environments.

Beyond core connectivity, the system provides extensive tooling for infrastructure governance, including automated access request workflows, device trust verification, and machine identity management for automated workloads. It supports broad observability through real-time audit event streaming, risk analysis, and health monitoring, ensuring consistent security policies are applied to both human users and autonomous agents.

The platform is deployed via lightweight access agents installed on remote resources, which establish secure outbound connections to the management cluster to bypass complex network configurations.

Features

  • Zero Trust Access - Provides identity-based, least-privileged access to infrastructure resources without relying on static credentials.
  • Remote Access - Provides unified access to remote server resources through web-based terminals or command-line interfaces to manage distributed environments from any location.
  • Identity-Based Tunnels - Connects users to remote infrastructure through identity-based tunnels to remove the complexity and security risks of traditional VPNs.
  • Authentication Gateways - A centralized control plane that consolidates authentication and authorization workflows across distributed, multi-cloud, and on-premises environments.
  • Identity-Aware Proxies - A secure connectivity layer that replaces traditional VPNs by routing traffic through identity-verified tunnels to internal applications and resources.
  • Federated Access - The platform establishes trust between independent clusters to allow users to access resources across multiple environments through a single authentication point.
  • Infrastructure - The platform captures interactive session activity and protocol-level events across infrastructure resources to provide a comprehensive audit trail for compliance.
  • Self-Hosted Infrastructure Platforms - Sets up centralized management infrastructure to coordinate identity verification, audit logging, and unified access control across distributed environments.
  • Access Auditing - The platform records and logs detailed events for all infrastructure interactions to provide a comprehensive trail of user and machine activity.
  • Credential Lifecycle Management - Automates the issuance, rotation, and expiration of short-lived digital identities to eliminate standing access and long-term secret exposure.
  • Mutual Authentication - Requires mutual identity verification between clients and servers using cryptographic certificates for all communications.
  • Privileged Access Management - A security solution that enforces role-based access controls, session recording, and audit logging for sensitive infrastructure and administrative tasks.
  • Role-Based Access Control - Enforces granular authorization policies by mapping external identity provider claims to specific infrastructure permissions and ephemeral user privileges.
  • Deployment Agents - Installs lightweight services on remote servers or databases to establish secure, identity-based connectivity and enforce access policies.
  • Remote Access Clients - Provides command-line and desktop utilities to authenticate users and manage secure connections to remote infrastructure resources.
  • Ephemeral Certificate Issuance - The platform generates digital credentials with brief validity periods that automatically expire to reduce the risk of unauthorized access from compromised or stolen secrets.
  • Access Request Orchestrators - Automates the lifecycle of infrastructure access requests through approval routing and role-based policy enforcement.
  • Audit and Compliance - Recording detailed session logs and system events across distributed environments to maintain a searchable trail for security monitoring.
  • Mutual TLS Authentication - Terminates and inspects encrypted traffic at the edge to enforce identity verification and security policies between clients and internal services.
  • Security Monitoring - The platform analyzes access patterns and infrastructure configurations to detect vulnerabilities and anomalous behavior across human and machine identities.
  • Identity Federation Providers - The platform connects to existing identity providers to issue short-lived certificates or act as a service provider for secure application access.
  • Just-in-Time Access - Grants temporary, time-limited infrastructure permissions that automatically expire to minimize standing access risks.
  • Machine Identity - The platform automates the lifecycle of credentials for services and bots to enable secure, identity-based access for workloads and continuous integration pipelines.
  • Single Sign-On Solutions - The platform consolidates user authentication across multiple applications by connecting to centralized identity providers to simplify access management and improve security.
  • Audit Logging Systems - Captures and centralizes session logs, command execution, and system events across heterogeneous environments into a unified, searchable audit trail.
  • Overlay Networks - Control plane for secure access to infrastructure and applications.
  • Server Infrastructure - Modern SSH server designed for clusters and team access.
  • Service Governance and Platforms - Infrastructure access gateway based on zero-trust security models.
  • Security and Compliance - Access plane for infrastructure and applications.
  • Security And Privacy - Access plane for secure SSH, Kubernetes, and database connections.
  • Security & Privacy - Access plane for secure SSH, Kubernetes, and database connectivity.
  • Kubernetes Cluster Management - Connects Kubernetes clusters to a centralized management plane through automated discovery or manual agent deployment across various environments.
  • Reverse Tunnels - Establishes secure outbound connections from private resources to a central control plane to bypass complex firewall and network configurations.
  • Database Identity Mapping - Eliminates shared database accounts by automatically mapping users to individual database identities upon connection.
  • Passwordless Authentication - The platform verifies user identity using hardware keys and cryptographic tokens to eliminate the need for traditional passwords during the login process.
  • Kubernetes Security - Managing unified authentication and role-based access control for multiple Kubernetes clusters through a centralized identity-aware gateway.
  • Policy-Based Access Control - Enforces granular security permissions and access restrictions based on centralized role-based authorization policies.
  • Inline Risk Analysis - The platform identifies over-privileged users and detects security risks like exposed keys to maintain a secure access posture.
  • Secure Web Gateways - Exposes internal web applications through a secure gateway using unique subdomains and automated certificate management.
  • Cluster Configuration Management - Maintains dynamic resources including user roles, local accounts, and infrastructure definitions in a centralized registry.
  • Infrastructure Automation - Manages access resources and infrastructure state using command-line tools or configuration files to ensure consistent security policies across the environment.
  • CLI Authentication - Generates short-lived certificates for secure, identity-based authentication during command-line interface operations.
  • Multi-Factor Authentication - Enforces secondary identity verification requirements for all infrastructure access requests.
  • Secure Remote Access - Establishes encrypted, identity-verified tunnels for secure remote access to servers and databases.
  • Database Registration - Identifies and enrolls cloud-hosted or local databases into the access system without requiring service redeployment.
  • Infrastructure Discovery Tools - Automatically scans and enrolls infrastructure components like servers, databases, and clusters into the centralized access management system.
  • Host Networking Services - The platform runs authentication and proxy services within isolated containers to manage secure connectivity for servers, databases, and applications.
  • AI Agent Security - Provides secure, audited access controls for autonomous agents interacting with infrastructure and databases.
  • Biometric Authentication - The platform verifies user identity using biometric hardware to enable secure, passwordless login flows for protected infrastructure and applications.
  • Trust Verification - Validates device integrity and hardware authorization before granting access to protected infrastructure resources.

Star history

Star history chart for gravitational/teleportStar history chart for gravitational/teleport

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Teleport

These projects share indexed features with Teleport. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • fosrl/pangolinfosrl avatar

    fosrl/pangolin

    21,255View on GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    View on GitHub↗21,255
  • octelium/octeliumoctelium avatar

    octelium/octelium

    3,371View on GitHub↗

    Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,

    Goabacai-gatewayapi-gateway
    View on GitHub↗3,371
  • openziti/zitiopenziti avatar

    openziti/ziti

    3,883View on GitHub↗

    Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend

    Goappsecgolangmesh
    View on GitHub↗3,883
  • casdoor/casdoorcasdoor avatar

    casdoor/casdoor

    13,814View on GitHub↗

    Casdoor is a centralized identity and access management platform that functions as an OAuth 2.0 authorization server. It provides a comprehensive suite of services for managing user identities, authentication sessions, and access policies across both web and machine-to-machine applications. Built with a decoupled frontend-backend architecture in Go, the platform supports high-concurrency environments and offers a web-based management interface for administrative tasks. The platform distinguishes itself through its extensive support for federated identity management, allowing integration with

    Goai-gatewayauthauthentication
    View on GitHub↗13,814
Compare all 30 related projects→

Frequently asked questions

What does gravitational/teleport do?

Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers, databases, and Kubernetes clusters. It functions as a centralized gateway that replaces static credentials with short-lived, identity-bound cryptographic certificates, effectively eliminating the need for traditional VPNs and long-term secret exposure.

What are the main features of gravitational/teleport?

The main features of gravitational/teleport are: Zero Trust Access, Remote Access, Identity-Based Tunnels, Authentication Gateways, Identity-Aware Proxies, Federated Access, Infrastructure, Self-Hosted Infrastructure Platforms.

Which projects share features with gravitational/teleport?

Projects with overlapping indexed features include: fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… openziti/ziti — Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that… casdoor/casdoor — Casdoor is a centralized identity and access management platform that functions as an OAuth 2.0 authorization server.… apereo/cas — This project is an open-source identity provider and single sign-on platform that centralizes user authentication for… ockam-network/ockam — Ockam is an end-to-end encryption framework and distributed identity provider designed to establish secure…