Netflix/bless
Repository for BLESS, an SSH Certificate Authority that runs as a AWS Lambda function observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3759
- days_rel: n/a
- days_push: 747
- n_releases_24m: 0
Adoption not part of the score
2758 stars · 229 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
BLESS is an SSH Certificate Authority that runs as an AWS Lambda function and signs short-lived SSH certificates for user authentication. It lets hosts trust a single SSH CA instead of managing authorized_keys files, with access controlled via IAM policies.
Use cases
- sign short-lived ssh certificates via aws lambda
- replace authorized_keys management with an ssh certificate authority
- secure ssh bastion access with ephemeral credentials
- restrict which iam roles can request ssh certificates
- run an ssh ca in an isolated aws account
When to choose
- you already run BLESS or are committed to an AWS Lambda-based SSH CA
- you need short-lived SSH certificates tied to IAM roles on AWS
When to avoid
- starting a new project - the repo is archived and unmaintained
- you want actively maintained alternatives like step-ca or AWS-native SSH access management
- you are not deploying on AWS Lambda
Facets
service · maturity abandoned
security cryptography auth serverless security cloud-computing developer-tools self-hosted cloud python serverless windows ssh-certificates ssh-ca aws-lambda bastion short-lived-credentials archived linux macos
1 source
- readme: https://github.com/Netflix/bless · fetched 2026-08-28 · 32f50a1b3827
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Netflix/bless | main | 23 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem