# octelium/octelium

A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA platform, API/AI/MCP gateway, a PaaS, an ngrok-alternative and a homelab infrastructure.

Repository: https://github.com/octelium/octelium
Canonical: https://ross.abutalabs.com/products/octelium
Homepage: https://octelium.com/docs
Language: Go
License: AGPL-3.0
License Family: copyleft
Topics: abac, ai-gateway, api-gateway, beyondcorp, homelab, mfa, paas, policy-as-code, quic, remote-access, ssh, sso, vpn, wireguard, zero-trust, ztna, kubernetes, tunnel, mcp-gateway, opentelemetry
Last push: 2026-08-26T21:32:06+00:00

## Health v2 (maintenance only)
Score: 86/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 99, longevity 33
- inputs: {"age_days": 472, "days_push": 7, "days_rel": 10, "gap_med": 11, "n_releases_24m": 40}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4025, forks 149 (observed 2026-08-28T04:08:32.604794+00:00)

## What it is
Octelium is a free, open-source, self-hosted unified zero trust secure access platform built on Kubernetes. It can operate as a remote access VPN, ZTNA/BeyondCorp platform, secure tunnel alternative to ngrok, API/AI/MCP gateway, PaaS for containerized apps, and homelab infrastructure, with identity-based, per-request, L7-aware access control and secretless credential injection.

## Use cases
- self-hosted zero trust VPN alternative to Tailscale or OpenVPN
- ZTNA/BeyondCorp platform for securing internal apps and databases
- self-hosted ngrok or Cloudflare Tunnel alternative for exposing services behind NAT
- API gateway and AI/LLM gateway with identity-based access control
- build MCP gateways and AI agent access infrastructure
- deploy containerized apps with a PaaS-like workflow
- secure SSH and database access without sharing credentials
- homelab secure remote access infrastructure

## When to choose
- you want a self-hosted, unified replacement for VPNs, tunnels, bastion hosts, and gateways
- you need per-request, identity-based, context-aware access control with policy-as-code
- you want secretless access that injects credentials (API keys, DB passwords, SSH keys) on the fly
- you need client-based WireGuard/QUIC access plus clientless browser access for humans and workloads
- you want to expose, protect, and deploy services on top of Kubernetes with a kubectl-like CLI

## When to avoid
- you need a simple point-to-point VPN without zero trust policy overhead
- you cannot run Kubernetes or lack a Linux VM/server with a domain name
- you need a lightweight mesh networking tool rather than a full access platform
- you require a commercially supported product with SLAs rather than AGPL-3.0 FOSS

## Facets
- artifact type: application
- maturity: active
- function: auth, authorization, api-gateway, proxy, vpn, networking, security, secrets-management, deployment, microservices, mcp, middleware, http-server, ssh, self-hosted, container-orchestration
- domain: security, networking, self-hosted, infrastructure-as-code, cloud-computing, large-language-models, apis, backend, developer-tools
- platform: go, self-hosted, cloud, cli, cross-platform
- tags: zero-trust, ztna, beyondcorp, wireguard, quic, policy-as-code, abac, sso, mfa, tunnel, ngrok-alternative, paas, homelab, identity-aware-proxy, secretless-access, ai-gateway, mcp-gateway, remote-access, devops, containers, ai-agents, linux, kubernetes, docker

## Member repositories
- octelium/octelium (main) score 86

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:32.604794+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:23:54.266096+00:00, confidence not recorded.
  - readme: https://github.com/octelium/octelium (fetched 2026-08-28T04:08:32.604794+00:00, sha 8dd64a63c34f)
  - homepage: https://octelium.com/docs (fetched 2026-08-29T09:16:51.721820+00:00, sha 40d99ed701ec)
  - site_page: https://octelium.com/docs/octelium/latest/overview/how-octelium-works (fetched 2026-08-29T09:16:51.723554+00:00, sha cce9e1d172ab)
  - site_page: https://octelium.com/docs/octelium/latest/overview/quick-install (fetched 2026-08-29T09:16:51.725814+00:00, sha 4c7a5e7cebb1)
  - site_page: https://octelium.com/docs/octelium/latest/overview/management (fetched 2026-08-29T09:16:51.728356+00:00, sha 85be108fb205)
  - site_page: https://octelium.com/docs/octelium/latest/overview/zero-trust (fetched 2026-08-29T09:16:51.730632+00:00, sha 2b05ae04d0af)
  - site_page: https://octelium.com/docs/octelium/latest/overview/cli (fetched 2026-08-29T09:16:51.732450+00:00, sha 2d2b97e3b521)
  - site_page: https://octelium.com/docs/octelium/latest/management/core/service/managed-containers (fetched 2026-08-29T09:16:51.734014+00:00, sha 69b41cbe64b2)
  - site_page: https://octelium.com/docs/octelium/latest/management/core/service/secretless (fetched 2026-08-29T09:16:51.735776+00:00, sha 8a05fd192122)
- Data as of 2026-08-30T08:39:29.467469+00:00.
