Teleport

Teleport

Identity-native infrastructure access for SSH, Kubernetes, RDP and DBs

19.6kstars
2kforks
Last commit: 1d ago
Repo age: 11y old
Teleport screenshot

Teleport is an identity-native access platform that unifies secure access to infrastructure (SSH), Kubernetes, databases, web apps, and desktops through a single control plane. It focuses on eliminating long-lived credentials by using short-lived certificates and strong identity, while providing centralized visibility and audit trails.

Key Features

  • Unified access proxy for SSH, Kubernetes, databases, Windows desktops (RDP), and internal web apps
  • Short-lived, automatically issued certificates (no shared SSH keys) and session-based access
  • Built-in audit logging and session recording/playback (SSH and Kubernetes activity; RDP recording in supported editions)
  • Role-based access control (RBAC) with fine-grained policies and access workflows
  • Single sign-on integrations (e.g., SAML/OIDC providers) and device-aware access options
  • Infrastructure discovery and inventory (nodes, clusters, apps, databases) with a central web UI and CLI (tsh)
  • High availability and clustering for running Teleport at scale

Use Cases

  • Replace bastion hosts and shared SSH keys with centralized, identity-based SSH access
  • Provide secure, auditable Kubernetes access for platform and developer teams
  • Centralize database access with consistent authentication, authorization, and auditing

Limitations and Considerations

  • Some capabilities (notably certain enterprise features such as advanced access workflows/recording options) may require paid editions depending on your needs
  • Operational complexity can be higher than simple SSH bastions due to certificate-based architecture and multi-component deployment

Teleport is well-suited for organizations that want consistent authentication and auditing across multiple infrastructure access methods. It provides a single access plane that scales from small teams to multi-cluster environments while improving credential hygiene and traceability.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Bitwarden

Bitwarden

Open-source password manager for individuals and teams

17.8k
1.5k
Last commit: 1d ago

Self-hostable password manager with end-to-end encryption, vault sharing, TOTP, passkeys, and cross-platform apps plus browser extensions.

Alternative to:
1Password Secrets Sharing
1Password Secrets Sharing
+4
Documenso

Documenso

Open-source document signing and workflow platform

12.2k
2.2k
Last commit: 1d ago

Self-hosted platform for preparing, sending, and tracking legally binding e-signatures with templates, audit trails, and team workflows.

Alternative to:
DocuSign
DocuSign
+9
SFTPGo

SFTPGo

Secure, multi-protocol file transfer server with a web admin UI

11.6k
891
Last commit: 8d ago

Self-hosted SFTP/FTP/WebDAV server with web admin, virtual users, storage backends, and auditing for secure file exchange and managed file transfer workflows.

Alternative to:
WeTransfer
WeTransfer
+7
Sandstorm

Sandstorm

Personal cloud to run web apps securely, per-user sandboxed

7k
709
Last commit: 2mo ago

Self-hosted platform for running web apps with per-user sandboxes, easy install, app store packaging, and sharing via secure links and access controls.

Alternative to:
Heroku
Heroku
+9
Warpgate

Warpgate

Smart SSH bastion with web UI, RBAC, and audit logs

6.3k
224
Last commit: 2d ago

Self-hosted SSH bastion and access gateway with web UI, RBAC, just-in-time access, session recording, and audit logging for servers and infrastructure.

Alternative to:
Okta Advanced Server Access
Okta Advanced Server Access
+2
MeshCentral

MeshCentral

Open-source remote device management and remote access server

5.9k
776
Last commit: 1d ago

Web-based remote management server for computers and IoT devices with remote desktop/terminal, file transfer, user/device groups, and auditing.

Alternative to:
TeamViewer
TeamViewer
+6