Ross ROSS = Recommend OSS · open-source software intelligence for agents

AthenZ/athenz

Open source platform for X.509 certificate based service authentication and fine grained access control in dynamic infrastructures. Athenz supports provisioning and configuration (centralized authorization) use cases as well as serving/runtime (decentralized authorization) use cases. observed · 2026-09-03

github.com/AthenZ/athenz · homepage · Java · Apache-2.0 (permissive) observed · 2026-09-03

Health v2 · maintenance only

100/100

  • Activity 100
  • Release rhythm 99
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 14.0
  • age_days: 3577
  • days_rel: 9
  • days_push: 0
  • n_releases_24m: 49

Full methodology

Adoption not part of the score

1006 stars · 313 forks observed · 2026-09-03

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Athenz is an open source platform for X.509 certificate-based service authentication and fine-grained role-based access control (RBAC) in dynamic infrastructures. It issues short-lived service identity certificates to workloads in private or public clouds and supports both centralized authorization management and decentralized runtime authorization using mTLS-bound OAuth2 access tokens.

Use cases

  • issue short-lived x509 certificates to cloud workloads for service identity
  • implement role-based access control (rbac) for microservices
  • enable mutual tls authentication between services
  • provide workload identity for kubernetes pods
  • manage centralized authorization policies for dynamic infrastructure
  • issue mtls-bound oauth2 access tokens for service authorization
  • implement zero trust security in hybrid cloud environments

When to choose

  • you need workload/service identity via short-lived X.509 certificates across hybrid or multi-cloud environments
  • you want fine-grained RBAC with centralized management and decentralized runtime enforcement
  • you need mTLS-bound OAuth2 access tokens and zero trust principles for service-to-service communication
  • you want an open source alternative to SPIRE/SPIFFE-style identity with integrated authorization

When to avoid

  • you only need simple user-facing authentication like social login or SSO for web apps
  • your infrastructure is small and static where built-in cloud IAM suffices
  • you cannot operate the operational overhead of running certificate authorities and identity agents
  • you need only coarse-grained access control without role or policy management

Facets

service · maturity active

auth authorization security cryptography microservices api-gateway security cloud-computing microservices infrastructure-as-code developer-tools cloud self-hosted jvm go cross-platform rbac x509 mtls zero-trust service-identity oauth2 spiffe access-control identity-provider workload-identity containers kubernetes docker linux

2 sources

Member repositories

RepositoryRoleHealth v2
AthenZ/athenzmain100

For agents

markdown · JSON · MCP: product_card(name="AthenZ/athenz")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem