awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
hashicorp avatar

hashicorp/boundary

0
View on GitHub↗
4,041 stars·309 forks·Go·10 viewsboundaryproject.io↗

Boundary

Boundary is an identity-aware access proxy and privileged access management tool. It brokers secure network connections to infrastructure targets by mapping verified user identities to granular permissions, providing a gateway to servers and databases without the need for static credentials or VPNs.

The system distinguishes itself through just-in-time connectivity and automated credential injection, delivering short-lived secrets to users during session initialization. It implements a composable security model using allow-only role-based access control and hierarchical resource scoping to isolate security domains and limit blast radius.

The platform provides broad capabilities for infrastructure auditing, including session recording and dimensional audit logging for incident timeline reconstruction. It supports automated resource discovery from cloud platforms and manages network connectivity through worker nodes that bridge traffic to private networks. Authentication is handled via native accounts or through OpenID Connect identity bridging.

Boundary can be deployed as a self-managed installation or as a hosted cloud service.

Features

  • Infrastructure Access Proxies - Brokers secure network connections to private hosts and services without exposing the underlying network or requiring a VPN.
  • Identity-Aware Proxies - Brokers secure network connections to infrastructure by verifying user identity and permissions without requiring a VPN.
  • Encrypted Session Recordings - Encrypts session recording data and verifies integrity using dedicated keys for security compliance.
  • Permission Scoping - Organizes permissions into a nested structure of containers to implement inherited access control.
  • Local Proxy Connection Establishment - Creates a local proxy to authorized target systems and returns the connection address and port to the client.
  • Service Exposure - Maps internal IP addresses and host sets to secure endpoints to provide connectivity to internal services.
  • Access Auditing - Tracks and records the full lifecycle of administrative sessions to ensure compliance and support incident investigations.
  • Resource Containers - Organizes resources and permissions into a hierarchical structure of containers to limit the impact of security breaches.
  • Identity Authentication - Exchanges credentials via defined authentication methods and recovery workflows to obtain system access tokens.
  • External Identity Provider Integrations - Integrates with external identity providers via OpenID Connect to verify user identities.
  • Credential Injection - Integrates with secret stores to automatically inject short-lived credentials during session initialization.
  • Identity-Based Access Control - Implements network-level access control by mapping verified user identities to granular infrastructure permissions.
  • Credential Brokering - Surfaces short-lived static or dynamic secrets from credential stores to users during session initialization.
  • Just-in-Time Access - Enforces least-privilege access by granting temporary, time-limited network permissions to private resources based on roles.
  • OIDC Identity Integrations - Delegates authentication to external OIDC providers and maps token claims to internal access policies.
  • Privileged Access Management - Provides secure, audited connectivity to critical systems using just-in-time access and session recording.
  • Role-Based Access Control - Implements a security model where permissions are explicitly granted through roles assigned to principals.
  • SSL/TLS Connection Security - Establishes mutually authenticated TLS 1.3 connections between clients and workers using dynamic certificates.
  • User Identity Management - Creates and organizes users and groups into principals assigned specific capabilities across organizational levels.
  • Remote Session Audits - Records and tracks administrative activities performed during remote sessions to maintain a compliance trail.
  • Forensic Event Timelines - Produces chronological sequences of authorized and terminated events to reconstruct attacker activity during incidents.
  • Target Discovery - Locates cloud hosts and endpoints automatically to enable secure communication without manual entry.
  • Administrative Session Recording - The product captures and stores session activity using S3-compatible storage backends for auditing and security compliance.
  • Cloud Resource Discovery - Programmatically identifies and catalogs target systems and workloads as they are deployed across cloud platforms.
  • Private Network Bridge Workers - Registers worker nodes to bridge connectivity between the proxy and targets located in private networks.
  • Tag-Based Worker Routing - Controls which proxy workers handle specific resources by matching worker metadata tags against filter expressions.
  • Agent-Based Session Proxies - Provides network access to hosts and systems via a client agent to ensure compatibility with security software.
  • Connection and Session Management - Regulates the duration and number of simultaneous connections to target systems to prevent resource exhaustion.
  • Worker Node Routing - Routes traffic through worker nodes using metadata tags to bridge connectivity to private networks.
  • User Behavior Anomaly Detection - Identifies suspicious behavior such as lateral movement and data exfiltration via volume spikes.
  • External Key Integration - Integrates with external Key Management Services to handle encryption keys for secure data storage.
  • Data Encryption - Ensures that all sensitive system and session information is encrypted while residing on disk.
  • Encrypted Secret Management - Protects sensitive configuration values using an external key management system or transit engine.
  • Encryption Key Management - Automatically generates new key versions and re-encrypts existing data to maintain cryptographic security.
  • Key Hierarchies - Protects secrets using a hierarchy of root keys and data encryption keys across operational scopes.
  • Federated Identity Brokers - Brokers access by mapping claims from external OIDC providers to internal resource permissions.
  • RDP - Provides target credentials directly to users during RDP sessions to enable passwordless access.
  • Dynamic Target Mapping - Automatically discovers cloud targets and maps them to secure endpoints for authorized users.
  • Infrastructure Component Authentication - Uses shared keys to verify the identity of workers connecting to controllers in multi-hop deployments.
  • Network Connection Security - Utilizes TLS to encrypt communication channels between clients and the proxy to prevent interception.
  • Secure Token Storage - Saves session tokens in platform-specific secure credential stores to minimize manual authentication prompts.
  • Mutual TLS Transport Encryption - Establishes encrypted tunnels between clients and workers using dynamically generated certificates for mutual authentication.
  • Encrypted Communication Channels - Encrypts traffic between clients and the controller using PKI and optional client certificates.
  • Claim Filtering - Restricts user access based on specific claims extracted from OIDC identity provider tokens or UserInfo endpoints.
  • Inactive Account Reviews - Identifies inactive or orphaned accounts for access certification and security auditing.
  • Audit Logs - Captures session lifecycles and connection events into structured logs for SQL-based analytics.

Star history

Star history chart for hashicorp/boundaryStar history chart for hashicorp/boundary

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does hashicorp/boundary do?

Boundary is an identity-aware access proxy and privileged access management tool. It brokers secure network connections to infrastructure targets by mapping verified user identities to granular permissions, providing a gateway to servers and databases without the need for static credentials or VPNs.

What are the main features of hashicorp/boundary?

The main features of hashicorp/boundary are: Infrastructure Access Proxies, Identity-Aware Proxies, Encrypted Session Recordings, Permission Scoping, Local Proxy Connection Establishment, Service Exposure, Access Auditing, Resource Containers.

What are some open-source alternatives to hashicorp/boundary?

Open-source alternatives to hashicorp/boundary include: octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… langchain-ai/deepagents — Deepagents is an LLM agent orchestration platform and stateful application server designed for deploying and managing… microsoft/security-101 — Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular,… cube-js/cube — Cube is a semantic data layer that provides a unified framework for defining business metrics, dimensions, and… gravitational/teleport — Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers,… tailscale/tailscale — Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted…

Open-source alternatives to Boundary

Similar open-source projects, ranked by how many features they share with Boundary.
  • octelium/octeliumoctelium avatar

    octelium/octelium

    3,371View on GitHub↗

    Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,

    Goabacai-gatewayapi-gateway
    View on GitHub↗3,371
  • langchain-ai/deepagentslangchain-ai avatar

    langchain-ai/deepagents

    25,006View on GitHub↗

    Deepagents is an LLM agent orchestration platform and stateful application server designed for deploying and managing AI agents built with computational graphs. It provides a containerized runtime environment that handles agent execution, state persistence, and the versioning of AI assistants. The platform distinguishes itself through deep integration with the Model Context Protocol, allowing agents to function as servers that expose tools and capabilities to external clients. It features a sophisticated observability suite for capturing execution traces, performing LLM-based evaluations agai

    Pythonagentsdeepagentslangchain
    View on GitHub↗25,006
  • microsoft/security-101microsoft avatar

    microsoft/Security-101

    6,203View on GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    HTMLappseccia-triaddata-protection
    View on GitHub↗6,203
  • cube-js/cubecube-js avatar

    cube-js/cube

    20,251View on GitHub↗

    Cube is a semantic data layer that provides a unified framework for defining business metrics, dimensions, and relationships across diverse data sources. By acting as a headless business intelligence engine, it transforms raw data into a governed model that can be queried via SQL, REST, and GraphQL interfaces. This architecture ensures consistent data definitions and logic across all downstream analytical applications and reporting tools. The platform distinguishes itself through its integrated conversational AI capabilities, which allow users to explore data using natural language. It orches

    Rustagentic-analyticsagentsai
    View on GitHub↗20,251
  • See all 30 alternatives to Boundary→