Ross ROSS = Recommend OSS · open-source software intelligence for agents

paralus/paralus

All-in-one Kubernetes access manager. User-level credentials, RBAC, SSO, audit logs. observed · 2026-08-28

github.com/paralus/paralus · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

71/100

  • Activity 87
  • Release rhythm 34
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 237
  • age_days: 1545
  • days_rel: 229
  • days_push: 78
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1209 stars · 83 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Paralus is an open source, CNCF Sandbox zero-trust Kubernetes access manager that provides controlled, audited access to Kubernetes clusters. It ships as a web GUI, REST API, and CLI (pctl), integrating with existing RBAC and SSO/OIDC identity providers with just-in-time service accounts and real-time audit logs.

Use cases

  • manage kubectl access across a fleet of Kubernetes clusters
  • centralize Kubernetes RBAC instead of configuring it per cluster
  • integrate SSO/OIDC providers like Okta, Azure AD, or Google for cluster access
  • audit who accessed which cluster and namespace
  • grant just-in-time temporary access to contractors or developers
  • dynamically revoke Kubernetes permissions in response to threats
  • achieve zero-trust security for Kubernetes infrastructure

When to choose

  • you manage many Kubernetes clusters across clouds and on-prem and need centralized access control
  • you need user-level audit logs for compliance
  • you want zero-trust, least-privilege access with dynamic revocation
  • you want to keep existing SSO and kubectl workflows

When to avoid

  • you have a single small cluster where native RBAC suffices
  • you need a fully managed SaaS rather than self-hosted Helm deployment
  • you don't use Kubernetes at all

Facets

service · maturity active

auth authorization security api-framework web-framework cli self-hosted security cloud-computing self-hosted infrastructure-as-code go self-hosted cli cross-platform kubernetes-access-management zero-trust rbac sso audit-logs ztka cncf-sandbox kubectl-access audit containers devops kubernetes docker web-server

3 sources

Member repositories

RepositoryRoleHealth v2
paralus/paralusmain71

For agents

markdown · JSON · MCP: product_card(name="paralus/paralus")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem