
Warpgate
Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL
7.7k stars 356 forks last commit first released Apache-2.0
Actively maintained
Last commit 26 Aug 2026.

Warpgate is a transparent bastion host and privileged access management (PAM) service for securing access to internal SSH, HTTPS, MySQL, and PostgreSQL targets. It authenticates users, forwards connections directly to the target service without client wrappers, and provides auditing through an admin web UI.
Key Features
- Native listeners for SSH, HTTPS, MySQL, and PostgreSQL, with transparent forwarding to target services
- Role-based access control (RBAC) with precise user-to-service assignments
- Session recording with live view and replay for auditing
- Built-in admin web UI to manage users, targets, access, and session history
- SSO and 2FA support, including OpenID Connect and TOTP
- Single-binary deployment with minimal operational dependencies
Use Cases
- Secure controlled access to production servers and databases without VPNs or jump host configuration
- Audited contractor or third-party access with session replay and command-level visibility
- Acting as a proxy entrypoint for internal HTTPS services (including developer tooling endpoints)
Limitations and Considerations
- Default session history storage uses SQLite, which may not fit all scaling/HA requirements
Warpgate is suited for teams that need strong access controls, auditability, and SSO-backed authentication for infrastructure services while keeping client connections fully standard. It is particularly useful when you want bastion-like security without broad network access exposure.
Categories:
Tags:
Tech Stack:
Similar to Warpgate

Teleport
Identity-aware access proxy for infrastructure and internal apps
Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

ZITADEL
API-first identity and access management platform for applications
ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

Logto
Authentication and authorization platform for apps and APIs
Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Defguard
Zero-trust WireGuard VPN with protocol-level MFA and integrated SSO
Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

Termix
Web-based SSH server management with tunneling and file editing
Self-hosted server management platform with web SSH terminal, SSH tunneling, remote file manager/editor, Docker controls, monitoring, and RBAC with OIDC and 2FA.

OAuth2 Proxy
Reverse proxy and middleware for OAuth2/OIDC authentication
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.




