# jumpserver/jumpserver

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser.

Repository: https://github.com/jumpserver/jumpserver
Canonical: https://ross.abutalabs.com/products/jumpserver
Homepage: https://jumpserver.com
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: python, ssh-server, django, terminal, bastion-host, cyberark, teleport, pam, jumpserver
Last push: 2026-08-26T11:30:14+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 4443, "days_push": 7, "days_rel": 9, "gap_med": 8.5, "n_releases_24m": 41}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 31455, forks 5772 (observed 2026-08-28T04:11:56.880043+00:00)

## What it is
JumpServer is an open-source Privileged Access Management (PAM) platform and bastion host that provides secure, audited access to SSH, RDP, Kubernetes, database, and RemoteApp endpoints through a web browser. It consolidates authentication (MFA, LDAP/AD, SSO), RBAC, credential rotation, session recording, and command filtering into a self-hosted platform deployable via Docker Compose or Helm.

## Use cases
- manage privileged access to servers and databases
- set up a bastion host / jump server for SSH and RDP
- record and audit terminal sessions of DevOps teams
- rotate and vault privileged account credentials automatically
- enforce RBAC and just-in-time access approvals
- replace CyberArk or Teleport with an open-source PAM
- give contractors browser-based access without VPN

## When to choose
- you need self-hosted, open-source PAM with session recording and auditing
- you want a bastion host supporting SSH, RDP, VNC, databases, and Kubernetes in one platform
- you need MFA, LDAP/AD integration, and command-level access control
- you want to eliminate shared accounts with automated password rotation

## When to avoid
- you only need simple SSH key management without access governance
- you require enterprise SSO (SAML/OIDC), multi-tenancy, or HA clustering on a free license
- you need a lightweight proxy rather than a full PAM platform with a 4c8g+ server footprint

## Facets
- artifact type: application
- maturity: stable
- function: auth, authorization, security, ssh, self-hosted, monitoring, http-server
- domain: security, self-hosted, backend, infrastructure-as-code
- platform: self-hosted, python
- tags: pam, bastion-host, privileged-access-management, session-recording, rbac, jump-host, audit, mfa, credential-management, devops, linux, docker, web-server

## Member repositories
- jumpserver/jumpserver (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:56.880043+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:52:16.774057+00:00, confidence not recorded.
  - readme: https://github.com/jumpserver/jumpserver (fetched 2026-08-28T04:11:56.880043+00:00, sha cf08bdafde9f)
  - homepage: https://jumpserver.com (fetched 2026-08-29T07:49:22.903378+00:00, sha 5c2493576594)
  - site_page: https://www.jumpserver.com/features (fetched 2026-08-29T07:49:22.913370+00:00, sha bfca208c7b97)
  - site_page: https://www.jumpserver.com/docs (fetched 2026-08-29T07:49:22.918661+00:00, sha 0d8427557683)
  - site_page: https://www.jumpserver.com/about (fetched 2026-08-29T07:49:22.920851+00:00, sha dc029137d6d0)
  - site_page: https://www.jumpserver.com/docs/installation (fetched 2026-08-29T07:49:22.923275+00:00, sha f300ad8b3d50)
  - site_page: https://www.jumpserver.com/pricing (fetched 2026-08-29T07:49:22.916194+00:00, sha b05de3bfb1b3)
- Data as of 2026-08-30T08:39:29.467469+00:00.
