# warp-tech/warpgate

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

Repository: https://github.com/warp-tech/warpgate
Canonical: https://ross.abutalabs.com/products/warpgate
Homepage: https://warpgate.null.page
Language: Rust
License: Apache-2.0
License Family: permissive
Topics: bastion, bastion-host, infrastructure, ssh, ssh-server, proxy, rust, https, https-proxy, mysql, mysql-proxy, postgresql-proxy, pam, privileged-access-management, kubectl, kubernetes, rdp, rdp-access, rdp-gateway, vnc-server
Last push: 2026-08-26T22:29:10+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 1670, "days_push": 7, "days_rel": 7, "gap_med": 5, "n_releases_24m": 46}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 7726, forks 356 (observed 2026-08-28T04:10:02.594149+00:00)

## What it is
Warpgate is an open-source, clientless bastion host and privileged access management (PAM) tool written in Rust that transparently proxies SSH, HTTPS, Kubernetes, MySQL, PostgreSQL, RDP and VNC connections. It provides authentication (2FA, SSO, LDAP), role-based access control, brute-force protection, and live/replayable session recording through a built-in admin web UI, all as a single dependency-free binary.

## Use cases
- give contractors SSH access to internal servers without sharing keys or a VPN
- record and audit all SSH and database sessions for compliance
- provide browser-based SSH, RDP and VNC access to a DMZ network
- replace manual authorized_keys management with centralized RBAC
- proxy PostgreSQL and MySQL connections through a single audited entry point
- secure kubectl access to Kubernetes clusters with SSO
- self-host an open-source alternative to Teleport, StrongDM or Boundary

## When to choose
- you need clientless bastion access across many protocols (SSH, RDP, VNC, databases, HTTP, Kubernetes)
- you want session recording and live monitoring for audit purposes
- you prefer a single self-hosted binary with no SaaS dependency
- you need SSO, TOTP 2FA, LDAP and brute-force protection built in
- you want native clients (VSCode, DATABASE_URL, kubectl) to work transparently

## When to avoid
- you need a full zero-trust platform with device posture and certificate enrollment at Teleport's scale
- you only need a simple SSH jump host without auditing or access control
- you require commercial support SLAs without a paid contract
- you need Windows-native server deployment (it targets Linux/Docker)

## Facets
- artifact type: service
- maturity: active
- function: proxy, auth, authorization, security, self-hosted, networking, monitoring
- domain: security, infrastructure-as-code, self-hosted, networking, backend
- platform: self-hosted, rust
- tags: bastion-host, privileged-access-management, pam, ssh-proxy, rdp-gateway, vnc, session-recording, sso, 2fa, clientless, teleport-alternative, jump-host, devops, linux, docker, kubernetes, web-server

## Member repositories
- warp-tech/warpgate (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:02.594149+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:35:12.382491+00:00, confidence not recorded.
  - readme: https://github.com/warp-tech/warpgate (fetched 2026-08-28T04:10:02.594149+00:00, sha de637d1826f2)
  - homepage: https://warpgate.null.page (fetched 2026-08-29T08:31:24.674006+00:00, sha b0b9e41956d0)
  - site_page: https://warpgate.null.page/docs (fetched 2026-08-29T08:31:24.677072+00:00, sha 02b5eedc6f2c)
  - site_page: https://warpgate.null.page/getting-started-on-docker (fetched 2026-08-29T08:31:24.678789+00:00, sha 419b89d7bd54)
  - site_page: https://warpgate.null.page/getting-started (fetched 2026-08-29T08:31:24.680348+00:00, sha 5c2961aa5190)
  - site_page: https://warpgate.null.page/getting-started-on-helm (fetched 2026-08-29T08:31:24.682023+00:00, sha 95b75cbf6b2c)
  - site_page: https://warpgate.null.page/getting-started-on-kubernetes (fetched 2026-08-29T08:31:24.683688+00:00, sha 850314df2f0a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
