# hashicorp/boundary

Boundary enables identity-based access management for dynamic infrastructure.

Repository: https://github.com/hashicorp/boundary
Canonical: https://ross.abutalabs.com/products/boundary
Homepage: https://boundaryproject.io
Language: Go
License: NOASSERTION
License Family: other
Topics: hashicorp, security, zero-trust, hacktoberfest
Last push: 2026-08-26T17:47:09+00:00

## Health v2 (maintenance only)
Score: 89/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 69, longevity 100
- inputs: {"age_days": 2429, "days_push": 7, "days_rel": 125, "gap_med": 38, "n_releases_24m": 16}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4056, forks 317 (observed 2026-08-28T04:08:33.929055+00:00)

## What it is
HashiCorp Boundary is an identity-aware proxy that provides secure, least-privilege access to hosts and critical systems across clouds and on-prem networks. It integrates with OIDC identity providers, brokers static or Vault-generated dynamic credentials, and offers just-in-time network access without agents on end hosts.

## Use cases
- securely access SSH servers and databases without VPNs or bastion hosts
- grant just-in-time access to private cloud infrastructure based on user identity
- replace static SSH keys with per-session dynamic credentials from Vault
- authenticate engineers via Okta or Azure AD single sign-on before connecting to targets
- audit and record privileged sessions to critical systems
- automatically discover new endpoints and onboard them as access targets
- give contractors time-limited access to internal services without exposing the network

## When to choose
- you need identity-based, least-privilege access to dynamic cloud or hybrid infrastructure
- you want to eliminate long-lived credentials and VPN/bastion maintenance
- you already use HashiCorp Vault and Terraform and want integrated credential brokering and infrastructure-as-code management
- you need session recording and audit trails for compliance

## When to avoid
- you only need simple site-to-site networking or full mesh VPN between hosts
- you require a lightweight open-source-only solution with no enterprise feature gating (some features are commercial)
- your access needs are limited to a handful of static servers where plain SSH with keys suffices
- you cannot run a PostgreSQL database and KMS as external dependencies

## Facets
- artifact type: application
- maturity: active
- function: auth, authorization, security, networking, proxy, secrets-management, cli, api-framework
- domain: security, infrastructure-as-code, cloud-computing, self-hosted, networking
- platform: windows, go, cross-platform, self-hosted, cloud
- tags: identity-aware-proxy, zero-trust, just-in-time-access, privileged-access-management, bastion-alternative, oidc, vault-integration, session-recording, devops, linux, macos

## Member repositories
- hashicorp/boundary (main) score 89

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:33.929055+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:23:37.051046+00:00, confidence not recorded.
  - readme: https://github.com/hashicorp/boundary (fetched 2026-08-28T04:08:33.929055+00:00, sha 5c315ce077b1)
  - homepage: https://boundaryproject.io (fetched 2026-08-29T09:15:59.071508+00:00, sha 419b467f4934)
  - site_page: https://developer.hashicorp.com/hcp/docs/vault-radar (fetched 2026-08-29T09:15:59.075107+00:00, sha 558d122b761a)
  - site_page: https://developer.hashicorp.com/boundary/install/enterprise (fetched 2026-08-29T09:15:59.077181+00:00, sha dcc34da711a3)
  - site_page: https://developer.hashicorp.com/boundary/docs (fetched 2026-08-29T09:15:59.079076+00:00, sha 9fd2293fa304)
  - site_page: https://developer.hashicorp.com/boundary/docs/commands (fetched 2026-08-29T09:15:59.080780+00:00, sha 573d7894e161)
  - site_page: https://developer.hashicorp.com/boundary/api-docs (fetched 2026-08-29T09:15:59.083017+00:00, sha 7d84891263f7)
  - site_page: https://developer.hashicorp.com/boundary/docs/domain-model (fetched 2026-08-29T09:15:59.084654+00:00, sha 3e71017683f9)
  - site_page: https://developer.hashicorp.com/boundary/docs/overview/what-is-boundary (fetched 2026-08-29T09:15:59.086519+00:00, sha 04e9521572cb)
  - site_page: https://developer.hashicorp.com/boundary/tutorials/hcp-getting-started (fetched 2026-08-29T09:15:59.088323+00:00, sha 51264e0299d0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
