google / hiba
HIBA is a system built on top of regular OpenSSH certificate-based authentication that allows to manage flexible authorization of principals on pools of target hosts without the need to push customized authorized_users files periodically.
☆377Updated last week
Alternatives and similar repositories for hiba:
Users that are interested in hiba are comparing it to the libraries listed below
- Short term certificate based identity system (ssh/x509 ca + openidc)☆129Updated this week
- A non-interactive daemon for host management☆104Updated last week
- 🦐SSH Certificate Authority in a Lambda (on the barbie)☆117Updated 4 years ago
- Turn IP sockets into Unix domain sockets☆365Updated 8 months ago
- Silly usage of AWS EC2 IPv6 prefixes☆321Updated 3 years ago
- A jump-host SSH server that starts machines on-demand☆484Updated 4 years ago
- BeyondCorp-inspired HTTPS/SSO Access Proxy. Secure internal services outside your VPN/perimeter network during a zero-trust transition.☆251Updated 2 years ago
- Keyless Git signing using Sigstore☆974Updated last week
- tobab: the poor mans identity aware proxy, easy to use setup for beyondcorp in your homelab☆152Updated last year
- A configuration management system for Pets, not Cattle☆462Updated last year
- Kadeessh (formerly Caddy-SSH) is a general-purpose, extensible, modular, memory-safe SSH server built in Go☆547Updated 3 months ago
- Test ssh login key acceptance without having the private key☆217Updated 3 years ago
- build distroless images with alpine tools☆131Updated 2 years ago
- Simple Linux seccomp rules without writing any code☆472Updated 5 months ago
- 🦠 NVMe-TCP at your fingertips 🦠☆300Updated last month
- A fancy-schmancy tcpdump-esque TUI, programmed in Go.☆367Updated 2 years ago
- a virtual black hole file system that behaves like /dev/null☆295Updated 8 months ago
- Linux Process Discovery. C Library, Go bindings, Runtime.☆219Updated 2 years ago
- Reference implementation of OpenPubkey☆673Updated this week
- Tool and policy library for reviewing Google Kubernetes Engine clusters against best practices☆518Updated last week
- uber's ssh certificate pam module☆853Updated 2 years ago
- Imagine your SSH server only listens on an IPv6 address, and where the last 6 digits are changing every 30 seconds as a TOTP code...☆418Updated 3 years ago
- Inspect certificate authorities in container images☆230Updated this week
- PAL: A secret bootstrapping tool for Docker☆84Updated 5 months ago
- ORBOS - GitOps everything☆114Updated 2 years ago
- BSD socket API on steroids☆294Updated 5 months ago
- Run containerized, rootless applications with podman☆121Updated 2 years ago
- Wireguard based overlay network CNI plugin for kubernetes☆515Updated last year
- The IPv4 unicast extensions project - Making class-e (240/4), 0/8, 127/8, 225/8-232/8 generally usable - adding 419 million new IPs to t…☆150Updated last year
- eBPF Port Knocking Tool☆232Updated last year