awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Allowlist management tools

Ranking updated Jul 8, 2026

For a tool for managing network allowlists, the strongest matches are gravitational/teleport (Teleport is a comprehensive access platform that provides identity-based), hashicorp/boundary (Boundary is an identity-aware access proxy that manages granular) and fosrl/pangolin (Pangolin is a zero-trust network access platform that enforces). crowdsecurity/crowdsec and evilsocket/opensnitch round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Find the best allowlist management tools for your project. Compare top open-source options ranked by activity and stars to find the right fit.

Allowlist management tools

Find the best repos with AI.We'll search the best matching repositories with AI.
  • gravitational/teleportgravitational avatar

    gravitational/teleport

    19,863View on GitHub↗

    Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers, databases, and Kubernetes clusters. It functions as a centralized gateway that replaces static credentials with short-lived, identity-bound cryptographic certificates, effectively eliminating the need for traditional VPNs and long-term secret exposure. The platform distinguishes itself by orchestrating access through a unified control plane that maps external identity provider claims to granular, role-based infrastructure permissions. It enforces security through mutual TLS gateways an

    Teleport is a comprehensive access platform that provides identity-based RBAC, audit logging, and dynamic infrastructure connectivity, serving as a robust solution for enforcing granular access control across servers and clusters.

    GoAudit Logging SystemsRole-Based Access ControlAccess Auditing
    View on GitHub↗19,863
  • hashicorp/boundaryhashicorp avatar

    hashicorp/boundary

    4,041View on GitHub↗

    Boundary is an identity-aware access proxy and privileged access management tool. It brokers secure network connections to infrastructure targets by mapping verified user identities to granular permissions, providing a gateway to servers and databases without the need for static credentials or VPNs. The system distinguishes itself through just-in-time connectivity and automated credential injection, delivering short-lived secrets to users during session initialization. It implements a composable security model using allow-only role-based access control and hierarchical resource scoping to iso

    Boundary is an identity-aware access proxy that manages granular, role-based access to infrastructure, effectively serving as a modern alternative to traditional network-level allowlist management by enforcing access policies at the session level.

    GoAudit LogsRole-Based Access ControlAccess Auditing
    View on GitHub↗4,041
  • fosrl/pangolinfosrl avatar

    fosrl/pangolin

    21,255View on GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    Pangolin is a zero-trust network access platform that enforces identity-aware access control and traffic filtering, providing the core functionality required for managing infrastructure security policies.

    TypeScriptAudit LoggingRole-Based Access ControlNetwork Access Controls
    View on GitHub↗21,255
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    CrowdSec is a security engine that manages and enforces network-level access control and filtering rules through its bouncer architecture, providing the IP filtering, API-driven configuration, and audit logging required for infrastructure protection.

    GoNetwork Access ControlsNetwork Access Controls
    View on GitHub↗12,574
  • evilsocket/opensnitchevilsocket avatar

    evilsocket/opensnitch

    12,899View on GitHub↗

    Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in real time. By hooking into kernel-level interfaces, it tracks system-wide network activity and maps connection attempts to specific local processes, allowing users to explicitly permit or deny traffic on a per-application basis. The project distinguishes itself through its ability to manage security policies across multiple distributed nodes from a single, unified dashboard. This centralized management is secured via encrypted socket communication, enabling consistent rule en

    Opensnitch is a host-based application firewall that provides granular network filtering and policy enforcement, serving as a capable tool for managing outbound access control rules on Linux systems.

    PythonSecurity Audit Logs
    View on GitHub↗12,899
  • cerbos/cerboscerbos avatar

    cerbos/cerbos

    4,460View on GitHub↗

    Cerbos is an open-source authorization service that provides a centralized, language-agnostic engine for managing access control. It functions as a policy-as-code platform, allowing teams to define, test, and distribute authorization rules using declarative YAML or JSON configurations. By decoupling access logic from application code, it enables consistent permission enforcement across diverse service stacks. The project distinguishes itself through its ability to translate high-level authorization policies into native database query filters. This capability allows applications to enforce sec

    Cerbos is a policy-as-code authorization engine that provides centralized RBAC and attribute-based access control with API-driven configuration and audit logging, making it a robust tool for managing application-level access policies.

    GoAudit LoggingAudit LogsRole-Based Access Control
    View on GitHub↗4,460
  • traefik/traefiktraefik avatar

    traefik/traefik

    63,644View on GitHub↗

    Traefik is a cloud-native edge router and API gateway designed to manage service communication and traffic flow across distributed infrastructure. It functions as a dynamic service proxy that automatically discovers backend services and configures routing rules in real time, eliminating the need for manual restarts or complex configuration updates. By integrating directly with container orchestrators and service registries, it maintains a consistent state for network traffic, load balancing, and security policy enforcement. The project distinguishes itself through its deep integration with di

    Traefik is a dynamic edge router and API gateway that provides robust traffic filtering, middleware-based access control, and audit logging, making it a highly effective tool for enforcing network and security policies across infrastructure.

    GoAPI GatewaysAPI Traffic ManagementAutomated Traffic Routing
    View on GitHub↗63,644
  • istio/istioistio avatar

    istio/istio

    38,226View on GitHub↗

    Istio is a service mesh infrastructure that provides a centralized control plane to manage, secure, and observe communication between distributed microservices. It functions as a policy-driven network traffic controller, enabling developers to route, balance, and secure service-to-service traffic without requiring modifications to application code. The system enforces zero-trust security by utilizing mutual transport layer authentication to verify cryptographic identities for every network request. The project distinguishes itself through a sidecar-less proxy architecture, which offloads netw

    Istio is a comprehensive service mesh that provides robust, API-driven network traffic control, including Layer 4 and Layer 7 authorization policies and audit-ready security enforcement, making it a powerful tool for managing infrastructure-level access control.

    GoService Mesh Control PlanesService MeshesSidecarless Service Meshes
    View on GitHub↗38,226
  • envoyproxy/envoyenvoyproxy avatar

    envoyproxy/envoy

    27,630View on GitHub↗

    Envoy is a high-performance, cloud-native service proxy designed for service-to-service communication in distributed architectures. It functions as a service mesh data plane, providing a centralized mechanism for managing, securing, and observing network traffic between microservices. The project is distinguished by its ability to perform dynamic traffic management and configuration updates in real-time without requiring service restarts or downtime. It utilizes a non-blocking, event-driven architecture to handle high-concurrency connections and supports hot-restart process management, which

    Envoy is a high-performance service proxy that provides the core infrastructure for network filtering, RBAC, and dynamic traffic management, making it a powerful tool for enforcing access control policies in distributed environments.

    C++Service MeshService ProxiesDynamic Configuration Managers
    View on GitHub↗27,630
  • fairwindsops/rbac-managerFairwindsOps avatar

    FairwindsOps/rbac-manager

    1,654View on GitHub↗

    RBAC Manager is a Kubernetes operator that automates the management of role-based access control and service account permissions. It functions as a controller that synchronizes cluster authorization resources with user-defined configuration files, ensuring that security settings remain consistent with established requirements. The system operates by monitoring the cluster API for changes and reconciling the current state against declarative manifests. By treating authorization as infrastructure as code, it enables teams to manage permissions through version-controlled files rather than manual

    This Kubernetes operator automates the management of RBAC roles and service accounts, providing a declarative, API-driven way to enforce access control within a cluster environment.

    GoKubernetes OperatorsCluster Access ControlDeclarative Access Control
    View on GitHub↗1,654
  • safing/portmastersafing avatar

    safing/portmaster

    13,003View on GitHub↗

    Portmaster is a host-based network firewall and privacy tool that monitors and controls all system network traffic. It operates by intercepting data packets at the operating system level, allowing it to observe and manage every connection made by local software in real time. The software distinguishes itself through process-aware connection mapping, which correlates active network sockets with specific local applications to provide visibility into data transfers. It utilizes a user-space policy engine to enforce granular security rules, enabling users to restrict internet access, block specif

    Portmaster is a host-based firewall that provides granular, process-aware network access control and filtering, making it a suitable tool for managing application-level traffic rules on individual systems.

    GoFirewallsDNS FilteringPrivacy-Focused Tools
    View on GitHub↗13,003
  • slackhq/nebulaslackhq avatar

    slackhq/nebula

    17,405View on GitHub↗

    Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer connections between distributed hosts. By utilizing a certificate-based identity authority, it enables the construction of private communication fabrics across disparate physical infrastructures, such as multiple cloud providers or on-premises data centers, without requiring central authentication servers. The project distinguishes itself through a zero-trust architecture that enforces granular, policy-driven firewall filtering based on certificate-derived group memberships. It facili

    Nebula is a decentralized overlay network that enforces granular, policy-driven firewall rules and access control based on certificate-derived identities, making it a robust tool for managing network-level access policies.

    GoCertificate AuthoritiesMesh NetworkingOverlay Networks
    View on GitHub↗17,405
  • netbirdio/netbirdnetbirdio avatar

    netbirdio/netbird

    26,188View on GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    NetBird is a zero-trust networking platform that provides identity-based access control, network segmentation, and granular filtering for distributed infrastructure, aligning well with the requirements for managing secure access and network rules.

    GoMesh NetworkingZero Trust NetworkingControl Planes
    View on GitHub↗26,188
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
gravitational/teleport19.9KGoagpl-3.0Feb 20, 2026
hashicorp/boundary4KGoNOASSERTIONJun 9, 2026
fosrl/pangolin21.3KTypeScriptNOASSERTIONJun 16, 2026
crowdsecurity/crowdsec12.6KGomitFeb 19, 2026
evilsocket/opensnitch12.9KPythongpl-3.0Feb 18, 2026
cerbos/cerbos4.5KGoApache-2.0Jun 16, 2026
traefik/traefik63.6KGoMITJun 16, 2026
istio/istio38.2KGoApache-2.0Jun 16, 2026
envoyproxy/envoy27.6KC++apache-2.0Feb 19, 2026
fairwindsops/rbac-manager1.7KGoApache-2.0May 5, 2026

Related searches

  • License compliance tool
  • Content filtering lists
  • an open source framework for access control
  • Network access control
  • Authentication library
  • Form management library
  • Container maintenance tools
  • License management tool