# veops/oneterm

Provide secure access and control over all infrastructure

Repository: https://github.com/veops/oneterm
Canonical: https://ross.abutalabs.com/products/oneterm
Homepage: https://www.v1ops.com
Language: Go
License: AGPL-3.0
License Family: copyleft
Topics: golang, ssh, terminal, vue, oneterm, rdp, vnc, bastion
Last push: 2026-02-03T09:28:49+00:00

## Health v2 (maintenance only)
Score: 59/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 65, release rhythm 48, longevity 67
- inputs: {"age_days": 947, "days_push": 211, "days_rel": 351, "gap_med": 22, "n_releases_24m": 12}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1732, forks 181 (observed 2026-08-28T04:05:28.856981+00:00)

## What it is
OneTerm is a lightweight, flexible enterprise bastion host (jump server) built on the 4A model: authentication, authorization, account, and audit. It proxies SSH, RDP, and VNC access to internal infrastructure while recording sessions and enforcing access control.

## Use cases
- secure ssh access to internal servers through a bastion
- record and audit terminal sessions of ops teams
- restrict direct access to critical systems behind a jump server
- manage credentials and password policies for server access
- give contractors time-limited access to infrastructure
- proxy rdp and vnc sessions to windows and desktop hosts

## When to choose
- you need a self-hosted, lightweight alternative to commercial bastion solutions like JumpServer or Teleport
- your team primarily uses SSH with some RDP/VNC needs
- session recording and audit logs are compliance requirements
- you want a simple web UI for managing server access permissions

## When to avoid
- you need deep integrations with enterprise SSO/IdP ecosystems or large-scale multi-cluster support offered by mature tools like Teleport
- you require a fully open permissive license for commercial redistribution (AGPL-3.0 applies)
- you need cloud-maned zero-trust access rather than a self-hosted bastion

## Facets
- artifact type: application
- maturity: active
- function: auth, authorization, ssh, security, logging, self-hosted, gui
- domain: security, self-hosted, infrastructure-as-code
- platform: self-hosted, go
- tags: bastion-host, jump-server, pam, session-recording, rdp, vnc, 4a, audit, devops, linux, docker, web-server

## Member repositories
- veops/oneterm (main) score 59

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:28.856981+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:31:40.801549+00:00, confidence not recorded.
  - readme: https://github.com/veops/oneterm (fetched 2026-08-28T04:05:28.856981+00:00, sha 3e34583efc70)
- Data as of 2026-08-30T08:39:29.467469+00:00.
