Engity's Bifröst
SSH server with OpenID Connect and container/Kubernetes sessions
83 stars 2 forks last commit first released Apache-2.0
Actively maintained
Last commit 25 Aug 2026.

Bifröst is an advanced, SSH-protocol-compliant server designed as a modern bastion/jump host. It supports traditional public-key SSH authentication and OpenID Connect/OAuth2 identity providers, and can execute user sessions directly inside Docker containers or Kubernetes pods for isolated, ephemeral environments.
Key Features
- Full SSH protocol compatibility while supporting OpenID Connect/OAuth2 authentication alongside SSH keys
- Execute user sessions inside per-user Docker containers or directly inside Kubernetes pods
- Automatic user provisioning and cleanup based on configurable templates and idle timeouts
- "Remember me" behavior to temporarily cache provided public keys for faster reconnects during an active session
- Configurable execution environments with custom images, networks, and resource constraints
- Designed to replace OpenSSH as a bastion while integrating SSO identity providers for centralized access control
Use Cases
- Provide SSO-backed SSH access for developers, operators, or contractors without additional client tooling
- Offer ephemeral, isolated shells for diagnostics or support by launching users into containerized environments
- Grant direct access to a Kubernetes cluster by entering dedicated pods without port-forwarding or kubectl proxies
Limitations and Considerations
- Project is under active development; configuration model and CLI/API structure are reported as evolving and may change
- Not all enterprise features (advanced RBAC, extensive audit integrations) may be production-ready depending on deployment needs
Bifröst is suitable for teams that need SSO-integrated SSH access and ephemeral container/pod sessions. It combines SSH compatibility with modern identity and container orchestration workflows for streamlined, centrally-managed access.
Categories:
Tags:
Tech Stack:
Similar to Engity's Bifröst

Teleport
Identity-aware access proxy for infrastructure and internal apps
Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.


ShellHub
Centralized SSH gateway for remote access and device management
Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

OAuth2 Proxy
Reverse proxy and middleware for OAuth2/OIDC authentication
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

XPipe
Connection hub and remote file manager for managing server infrastructure
Desktop application that centralizes SSH, containers, VMs, Kubernetes and remote file management; integrates local CLI tools and syncs connection data via git.

Casdoor
UI-first IAM and SSO platform for modern authentication
Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.
Flint
Lightweight KVM/libvirt virtual machine manager with Web UI, CLI, and API
Flint is a lightweight KVM/libvirt VM management tool with an embedded web UI, CLI, and REST API, designed for fast provisioning and low overhead.



