Ross ROSS = Recommend OSS · open-source software intelligence for agents

hashicorp/boundary

Boundary enables identity-based access management for dynamic infrastructure. observed · 2026-08-28

github.com/hashicorp/boundary · homepage · Go · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

89/100

  • Activity 99
  • Release rhythm 69
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 38
  • age_days: 2429
  • days_rel: 125
  • days_push: 7
  • n_releases_24m: 16

Full methodology

Adoption not part of the score

4056 stars · 317 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

HashiCorp Boundary is an identity-aware proxy that provides secure, least-privilege access to hosts and critical systems across clouds and on-prem networks. It integrates with OIDC identity providers, brokers static or Vault-generated dynamic credentials, and offers just-in-time network access without agents on end hosts.

Use cases

  • securely access SSH servers and databases without VPNs or bastion hosts
  • grant just-in-time access to private cloud infrastructure based on user identity
  • replace static SSH keys with per-session dynamic credentials from Vault
  • authenticate engineers via Okta or Azure AD single sign-on before connecting to targets
  • audit and record privileged sessions to critical systems
  • automatically discover new endpoints and onboard them as access targets
  • give contractors time-limited access to internal services without exposing the network

When to choose

  • you need identity-based, least-privilege access to dynamic cloud or hybrid infrastructure
  • you want to eliminate long-lived credentials and VPN/bastion maintenance
  • you already use HashiCorp Vault and Terraform and want integrated credential brokering and infrastructure-as-code management
  • you need session recording and audit trails for compliance

When to avoid

  • you only need simple site-to-site networking or full mesh VPN between hosts
  • you require a lightweight open-source-only solution with no enterprise feature gating (some features are commercial)
  • your access needs are limited to a handful of static servers where plain SSH with keys suffices
  • you cannot run a PostgreSQL database and KMS as external dependencies

Facets

application · maturity active

auth authorization security networking proxy secrets-management cli api-framework security infrastructure-as-code cloud-computing self-hosted networking windows go cross-platform self-hosted cloud identity-aware-proxy zero-trust just-in-time-access privileged-access-management bastion-alternative oidc vault-integration session-recording devops linux macos

10 sources

Member repositories

RepositoryRoleHealth v2
hashicorp/boundarymain89

For agents

markdown · JSON · MCP: product_card(name="hashicorp/boundary")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem