# paralus/paralus

All-in-one Kubernetes access manager. User-level credentials, RBAC, SSO, audit logs.

Repository: https://github.com/paralus/paralus
Canonical: https://ross.abutalabs.com/products/paralus
Homepage: https://www.paralus.io/
Language: Go
License: Apache-2.0
License Family: permissive
Topics: access-management, cloud-security, k8s-access-management, kubernetes-security, zero-trust-security, ztka
Last push: 2026-06-16T15:19:08+00:00

## Health v2 (maintenance only)
Score: 71/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 87, release rhythm 34, longevity 100
- inputs: {"age_days": 1545, "days_push": 78, "days_rel": 229, "gap_med": 237, "n_releases_24m": 2}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1209, forks 83 (observed 2026-08-28T04:03:59.792557+00:00)

## What it is
Paralus is an open source, CNCF Sandbox zero-trust Kubernetes access manager that provides controlled, audited access to Kubernetes clusters. It ships as a web GUI, REST API, and CLI (pctl), integrating with existing RBAC and SSO/OIDC identity providers with just-in-time service accounts and real-time audit logs.

## Use cases
- manage kubectl access across a fleet of Kubernetes clusters
- centralize Kubernetes RBAC instead of configuring it per cluster
- integrate SSO/OIDC providers like Okta, Azure AD, or Google for cluster access
- audit who accessed which cluster and namespace
- grant just-in-time temporary access to contractors or developers
- dynamically revoke Kubernetes permissions in response to threats
- achieve zero-trust security for Kubernetes infrastructure

## When to choose
- you manage many Kubernetes clusters across clouds and on-prem and need centralized access control
- you need user-level audit logs for compliance
- you want zero-trust, least-privilege access with dynamic revocation
- you want to keep existing SSO and kubectl workflows

## When to avoid
- you have a single small cluster where native RBAC suffices
- you need a fully managed SaaS rather than self-hosted Helm deployment
- you don't use Kubernetes at all

## Facets
- artifact type: service
- maturity: active
- function: auth, authorization, security, api-framework, web-framework, cli, self-hosted
- domain: security, cloud-computing, self-hosted, infrastructure-as-code
- platform: go, self-hosted, cli, cross-platform
- tags: kubernetes-access-management, zero-trust, rbac, sso, audit-logs, ztka, cncf-sandbox, kubectl-access, audit, containers, devops, kubernetes, docker, web-server

## Member repositories
- paralus/paralus (main) score 71

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:59.792557+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:18:36.248071+00:00, confidence not recorded.
  - readme: https://github.com/paralus/paralus (fetched 2026-08-28T04:03:59.792557+00:00, sha eb932c1c8b33)
  - homepage: https://www.paralus.io/ (fetched 2026-08-29T12:26:21.494185+00:00, sha ca6beedad5bd)
  - site_page: https://www.paralus.io/docs (fetched 2026-08-29T12:26:21.496580+00:00, sha 1ec6b094f3b9)
- Data as of 2026-08-30T08:39:29.467469+00:00.
