
Warpgate
Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL

Warpgate is a transparent bastion host and privileged access management (PAM) service for securing access to internal SSH, HTTPS, MySQL, and PostgreSQL targets. It authenticates users, forwards connections directly to the target service without client wrappers, and provides auditing through an admin web UI.
Key Features
- Native listeners for SSH, HTTPS, MySQL, and PostgreSQL, with transparent forwarding to target services
- Role-based access control (RBAC) with precise user-to-service assignments
- Session recording with live view and replay for auditing
- Built-in admin web UI to manage users, targets, access, and session history
- SSO and 2FA support, including OpenID Connect and TOTP
- Single-binary deployment with minimal operational dependencies
Use Cases
- Secure controlled access to production servers and databases without VPNs or jump host configuration
- Audited contractor or third-party access with session replay and command-level visibility
- Acting as a proxy entrypoint for internal HTTPS services (including developer tooling endpoints)
Limitations and Considerations
- Default session history storage uses SQLite, which may not fit all scaling/HA requirements
Warpgate is suited for teams that need strong access controls, auditability, and SSO-backed authentication for infrastructure services while keeping client connections fully standard. It is particularly useful when you want bastion-like security without broad network access exposure.
Categories:
Tags:
Tech Stack:
Similar Services

PocketBase
Lightweight open-source realtime backend with embedded SQLite
Open-source Go backend providing embedded SQLite, realtime (SSE) subscriptions, auth (JWT/OAuth2), file storage, admin UI and REST-style APIs for web and mobile apps.
Keycloak
Open-source identity and access management with SSO
Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Authelia
Self-hosted IAM with SSO and multi-factor authentication
Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.
Infisical
Open-source platform for secrets, PKI certificates, and privileged access
Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

authentik
Open-source Identity Provider (IdP) for SSO, OIDC, and SAML
Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Teleport
Identity-aware access proxy for infrastructure and internal apps
Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.





