Ross ROSS = Recommend OSS · open-source software intelligence for agents

octelium/octelium

A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA platform, API/AI/MCP gateway, a PaaS, an ngrok-alternative and a homelab infrastructure. observed · 2026-08-28

github.com/octelium/octelium · homepage · Go · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

86/100

  • Activity 99
  • Release rhythm 99
  • Longevity 33
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 11
  • age_days: 472
  • days_rel: 10
  • days_push: 7
  • n_releases_24m: 40

Full methodology

Adoption not part of the score

4025 stars · 149 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Octelium is a free, open-source, self-hosted unified zero trust secure access platform built on Kubernetes. It can operate as a remote access VPN, ZTNA/BeyondCorp platform, secure tunnel alternative to ngrok, API/AI/MCP gateway, PaaS for containerized apps, and homelab infrastructure, with identity-based, per-request, L7-aware access control and secretless credential injection.

Use cases

  • self-hosted zero trust VPN alternative to Tailscale or OpenVPN
  • ZTNA/BeyondCorp platform for securing internal apps and databases
  • self-hosted ngrok or Cloudflare Tunnel alternative for exposing services behind NAT
  • API gateway and AI/LLM gateway with identity-based access control
  • build MCP gateways and AI agent access infrastructure
  • deploy containerized apps with a PaaS-like workflow
  • secure SSH and database access without sharing credentials
  • homelab secure remote access infrastructure

When to choose

  • you want a self-hosted, unified replacement for VPNs, tunnels, bastion hosts, and gateways
  • you need per-request, identity-based, context-aware access control with policy-as-code
  • you want secretless access that injects credentials (API keys, DB passwords, SSH keys) on the fly
  • you need client-based WireGuard/QUIC access plus clientless browser access for humans and workloads
  • you want to expose, protect, and deploy services on top of Kubernetes with a kubectl-like CLI

When to avoid

  • you need a simple point-to-point VPN without zero trust policy overhead
  • you cannot run Kubernetes or lack a Linux VM/server with a domain name
  • you need a lightweight mesh networking tool rather than a full access platform
  • you require a commercially supported product with SLAs rather than AGPL-3.0 FOSS

Facets

application · maturity active

auth authorization api-gateway proxy vpn networking security secrets-management deployment microservices mcp middleware http-server ssh self-hosted container-orchestration security networking self-hosted infrastructure-as-code cloud-computing large-language-models apis backend developer-tools go self-hosted cloud cli cross-platform zero-trust ztna beyondcorp wireguard quic policy-as-code abac sso mfa tunnel ngrok-alternative paas homelab identity-aware-proxy secretless-access ai-gateway mcp-gateway remote-access devops containers ai-agents linux kubernetes docker

9 sources

Member repositories

RepositoryRoleHealth v2
octelium/octeliummain86

For agents

markdown · JSON · MCP: product_card(name="octelium/octelium")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem