google / hiba
HIBA is a system built on top of regular OpenSSH certificate-based authentication that allows to manage flexible authorization of principals on pools of target hosts without the need to push customized authorized_users files periodically.
☆373Updated last week
Alternatives and similar repositories for hiba:
Users that are interested in hiba are comparing it to the libraries listed below
- Progressively image a mounted disk correctly without corruption☆306Updated 3 years ago
- Short term certificate based identity system (ssh/x509 ca + openidc)☆128Updated this week
- Turn IP sockets into Unix domain sockets☆362Updated 7 months ago
- Silly usage of AWS EC2 IPv6 prefixes☆321Updated 3 years ago
- Test ssh login key acceptance without having the private key☆215Updated 3 years ago
- Imagine your SSH server only listens on an IPv6 address, and where the last 6 digits are changing every 30 seconds as a TOTP code...☆418Updated 3 years ago
- ssh-agent for TPMs☆407Updated 3 weeks ago
- 🦠 NVMe-TCP at your fingertips 🦠☆296Updated last week
- Simple Linux seccomp rules without writing any code☆470Updated 4 months ago
- build distroless images with alpine tools☆129Updated 2 years ago
- A configuration management system for Pets, not Cattle☆462Updated last year
- eBPF Port Knocking Tool☆232Updated last year
- Automate "airgapped" server proxy with ssh socks proxy☆101Updated 3 years ago
- Powerful system container and virtual machine manager☆66Updated this week
- Build a Firecracker microVM from a container image☆311Updated 4 months ago
- A UI for eBPF-based performance debugging☆561Updated 2 years ago
- A self-service CA for OpenSSH☆710Updated this week
- Keyless Git signing using Sigstore☆972Updated this week
- Inspect certificate authorities in container images☆229Updated 9 months ago
- runj is an experimental, proof-of-concept OCI-compatible runtime for FreeBSD jails.☆633Updated 8 months ago
- Tool and policy library for reviewing Google Kubernetes Engine clusters against best practices☆516Updated last month
- Tools for using PIV tokens (like Yubikeys) as an SSH agent, for encrypting data at rest, and more☆195Updated 2 weeks ago
- tobab: the poor mans identity aware proxy, easy to use setup for beyondcorp in your homelab☆152Updated last year
- uber's ssh certificate pam module☆849Updated last year
- BetterTLS: A Name Constraints test suite for HTTPS clients.☆167Updated 2 months ago
- A non-interactive daemon for host management☆104Updated this week
- Kadeessh (formerly Caddy-SSH) is a general-purpose, extensible, modular, memory-safe SSH server built in Go☆548Updated last month
- Linux Process Discovery. C Library, Go bindings, Runtime.☆220Updated 2 years ago
- A fancy-schmancy tcpdump-esque TUI, programmed in Go.☆367Updated 2 years ago
- Reference implementation of OpenPubkey☆667Updated this week