warp-tech/warpgate
Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 99
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 5
- age_days: 1670
- days_rel: 7
- days_push: 7
- n_releases_24m: 46
Adoption not part of the score
7726 stars · 356 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Warpgate is an open-source, clientless bastion host and privileged access management (PAM) tool written in Rust that transparently proxies SSH, HTTPS, Kubernetes, MySQL, PostgreSQL, RDP and VNC connections. It provides authentication (2FA, SSO, LDAP), role-based access control, brute-force protection, and live/replayable session recording through a built-in admin web UI, all as a single dependency-free binary.
Use cases
- give contractors SSH access to internal servers without sharing keys or a VPN
- record and audit all SSH and database sessions for compliance
- provide browser-based SSH, RDP and VNC access to a DMZ network
- replace manual authorized_keys management with centralized RBAC
- proxy PostgreSQL and MySQL connections through a single audited entry point
- secure kubectl access to Kubernetes clusters with SSO
- self-host an open-source alternative to Teleport, StrongDM or Boundary
When to choose
- you need clientless bastion access across many protocols (SSH, RDP, VNC, databases, HTTP, Kubernetes)
- you want session recording and live monitoring for audit purposes
- you prefer a single self-hosted binary with no SaaS dependency
- you need SSO, TOTP 2FA, LDAP and brute-force protection built in
- you want native clients (VSCode, DATABASE_URL, kubectl) to work transparently
When to avoid
- you need a full zero-trust platform with device posture and certificate enrollment at Teleport's scale
- you only need a simple SSH jump host without auditing or access control
- you require commercial support SLAs without a paid contract
- you need Windows-native server deployment (it targets Linux/Docker)
Facets
service · maturity active
proxy auth authorization security self-hosted networking monitoring security infrastructure-as-code self-hosted networking backend self-hosted rust bastion-host privileged-access-management pam ssh-proxy rdp-gateway vnc session-recording sso 2fa clientless teleport-alternative jump-host devops linux docker kubernetes web-server
7 sources
- readme: https://github.com/warp-tech/warpgate · fetched 2026-08-28 · de637d1826f2
- homepage: https://warpgate.null.page · fetched 2026-08-29 · b0b9e41956d0
- site_page: https://warpgate.null.page/docs · fetched 2026-08-29 · 02b5eedc6f2c
- site_page: https://warpgate.null.page/getting-started-on-docker · fetched 2026-08-29 · 419b89d7bd54
- site_page: https://warpgate.null.page/getting-started · fetched 2026-08-29 · 5c2961aa5190
- site_page: https://warpgate.null.page/getting-started-on-helm · fetched 2026-08-29 · 95b75cbf6b2c
- site_page: https://warpgate.null.page/getting-started-on-kubernetes · fetched 2026-08-29 · 850314df2f0a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| warp-tech/warpgate | main | 99 |
For agents
markdown · JSON · MCP: product_card(name="warp-tech/warpgate")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem