A transparent SSH, HTTPS, Kubernetes, MySQL, and PostgreSQL bastion host with built-in session recording and no client-side software required.
Warpgate is an open-source bastion host and Privileged Access Management (PAM) solution that provides secure, audited access to internal services like SSH, HTTPS, Kubernetes, MySQL, and PostgreSQL. It solves the problem of managing secure access to backend infrastructure without requiring custom client software or complex VPN setups. By acting as a transparent proxy, it enables precise user-to-service assignments with full session recording and built-in authentication.
System administrators, DevOps engineers, and security teams managing access to servers, databases, and Kubernetes clusters in production environments. It's ideal for organizations needing a self-hosted, auditable alternative to commercial PAM solutions.
Developers choose Warpgate because it offers a transparent, client-software-free approach to bastion hosting with out-of-the-box 2FA, SSO, and session recording. Unlike traditional jump hosts or VPNs, it provides precise access control without sacrificing auditability, all packaged as a single Rust binary for easy deployment.
Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Works with standard SSH, HTTPS, and database clients without any custom wrappers or plugins, as highlighted in the 'No custom client needed' comparison table.
Records every session for live viewing and replay with command-level audit trails stored in SQLite, providing full visibility into user actions.
Supports TOTP and OpenID Connect out of the box for 2FA and SSO, reducing the need for additional authentication setup.
Distributed as a single dependency-free binary written in Rust, making installation and setup straightforward with minimal dependencies.
Currently supports SSH, HTTPS, Kubernetes, MySQL, and PostgreSQL, but lacks native support for other common protocols like RDP or VNC, which might require additional solutions.
Uses SQLite for session storage by default, which may not be ideal for high-volume environments or distributed setups without manual database configuration.
Being self-hosted means teams are responsible for updates, security patches, and infrastructure management, unlike SaaS alternatives that handle these automatically.
Warpgate is an open-source alternative to the following products: