awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
openziti avatar

openziti/zrok

0
View on GitHub↗
4,477 星标·206 分支·Go·Apache-2.0·10 次浏览zrok.io↗

Zrok

zrok is a zero trust networking service that provides a secure overlay mesh to expose local services and files through firewalls and NAT without the need for manual port forwarding. It functions as a zero trust network manager, orchestrating identities, policies, and routers to establish secure connectivity between applications and users.

The project distinguishes itself through the use of identity-based routing and hardened HTTP frontends that integrate with external identity providers. These capabilities allow for the creation of identity-aware proxies and secure reverse proxies that authenticate users before granting access to internal web applications.

The platform's broader capabilities include peer-to-peer resource sharing for TCP and UDP services, network drive sharing, and identity-aware micro-segmentation for IT and operational technology networks. It also provides a programmatic interface via a secure sharing SDK to embed these tunneling capabilities directly into external applications.

The infrastructure can be deployed as a self-hosted controller and private network stack across Linux, Docker, or Kubernetes environments.

Features

  • Mesh Networking - Creates a secure overlay mesh network to connect peers without requiring firewall port forwarding.
  • Zero Trust Networking - Provides a secure overlay mesh for identity-based network communication that bypasses firewalls and NAT.
  • Infrastructure Orchestration - Provides a centralized platform for orchestrating identities, policies, and routers across the network.
  • Reverse Proxies with Integrated Security - Implements a hardened reverse proxy that enforces identity-based authentication before routing traffic to internal services.
  • Local Resource Exposure - Exposes local web applications to the public internet via secure encrypted tunnels without manual port forwarding.
  • Peer-to-Peer Tunneling - Establishes secure peer-to-peer connections for services and files without opening firewall ports.
  • Secure Local Service Exposure - Exposes local web applications or files to the internet through firewalls and NAT without manual port forwarding.
  • Centralized Security Agents - Uses a centralized management plane to push security policies to distributed agents that enforce connectivity.
  • Encrypted Tunneling - Encapsulates data within secure tunnels to bypass NAT and firewalls with end-to-end encryption.
  • Identity-Aware Proxies - Provides a gateway that verifies user identity through external providers to secure internal web applications.
  • Cryptographic Identity Networks - Directs network traffic based on cryptographically verified user identities instead of IP addresses.
  • Identity-Aware Web Gateways - Provides a secure entry point for web services that authenticates users via an external identity provider.
  • Orchestration Consoles - Provides a centralized console for orchestrating zero-trust identities, policies, and network routers.
  • Private Infrastructure Hosting - Supports deploying and managing a complete zero-trust networking stack on self-hosted or air-gapped hardware.
  • Self-Hosted Deployments - Provides automated installation for the controller, frontend, and data stores on private Linux servers.
  • Zero Trust Infrastructure Deployment - Supports installation and management of zero-trust infrastructure across Linux, Docker, and Kubernetes.
  • Network Drive Sharing - Turns local folders into shareable network drives accessible to remote users.
  • Network Stacks - Enables the deployment of a complete zero-trust networking stack within on-premises or air-gapped environments.
  • Network Tunneling Tools - Provides a utility for creating secure tunnels to expose local services to remote clients.
  • Secure Tunneling SDKs - Provides a secure sharing SDK for embedding tunneling capabilities directly into external applications.
  • External Identity Provider Integration - Requires users to verify their identity via external providers before accessing services through HTTP frontends.
  • External Resource Sharing - Provides secure connection methods for TCP and UDP services between specific users without public exposure.
  • Identity Provider Integrations - Hardens service entry points by delegating user verification to external identity providers.
  • Authenticated HTTP Gateways - Implements secure gateways that authenticate users via identity providers for browser-based access to HTTP services.
  • Micro-Segmentation Techniques - Enforces identity-aware security policies and observes traffic flows across IT and OT networks.
  • OT - Deploys firewall agents in operational technology environments to enforce identity-based security policies.
  • Embedded Zero Trust SDKs - Provides a secure sharing SDK to embed zero-trust tunneling capabilities directly into external applications.
  • Tunneling and Proxying - Effortless sharing for both public and private endpoints.

Star 历史

openziti/zrok 的 Star 历史图表openziti/zrok 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

常见问题解答

openziti/zrok 是做什么的?

zrok is a zero trust networking service that provides a secure overlay mesh to expose local services and files through firewalls and NAT without the need for manual port forwarding. It functions as a zero trust network manager, orchestrating identities, policies, and routers to establish secure connectivity between applications and users.

openziti/zrok 的主要功能有哪些?

openziti/zrok 的主要功能包括:Mesh Networking, Zero Trust Networking, Infrastructure Orchestration, Reverse Proxies with Integrated Security, Local Resource Exposure, Peer-to-Peer Tunneling, Secure Local Service Exposure, Centralized Security Agents。

openziti/zrok 有哪些开源替代品?

openziti/zrok 的开源替代品包括: netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the… firezone/firezone — Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to… fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… openziti/ziti — Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… build-trust/ockam — Ockam is a zero-trust networking framework designed to secure data transit between distributed applications using an…

Zrok 的开源替代方案

相似的开源项目,按与 Zrok 的功能重合度排序。
  • netbirdio/netbirdnetbirdio 的头像

    netbirdio/netbird

    26,188在 GitHub 上查看↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Gogolangmeshmesh-networks
    在 GitHub 上查看↗26,188
  • firezone/firezonefirezone 的头像

    firezone/firezone

    8,701在 GitHub 上查看↗

    Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to internal network resources. It functions as a virtual private network that synchronizes authentication and user groups via OpenID Connect providers. The system implements a group-based access control engine to enforce least privilege by restricting network resources to specific user groups. It utilizes holepunching and relay protocols for NAT traversal to establish encrypted tunnels through firewalls without requiring inbound ports. The platform includes a control plane for managing

    Elixirclouddevsecopselixir
    在 GitHub 上查看↗8,701
  • fosrl/pangolinfosrl 的头像

    fosrl/pangolin

    21,255在 GitHub 上查看↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    在 GitHub 上查看↗21,255
  • openziti/zitiopenziti 的头像

    openziti/ziti

    3,883在 GitHub 上查看↗

    Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend

    Goappsecgolangmesh
    在 GitHub 上查看↗3,883
查看 Zrok 的所有 30 个替代方案→