frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: I Spent Years Building a FOSS Unified Zero Trust Secure Access Platform

https://github.com/octelium/octelium
4•geoctl•5h ago
Hello HN, I've been working solo on Octelium for the past 5+ years now, (yes, you just read that correctly :|) along with a couple more sub-projects that will hopefully be released soon and I'd love to get some honest opinions from you. Octelium is simply an open source, self-hosted, unified platform for zero trust resource access that is primarily meant to be a modern alternative to corporate VPNs and remote access tools. It is built to be generic enough to not only operate as a ZTNA/BeyondCorp platform (i.e. alternative to Cloudflare Zero Trust, Google BeyondCorp, Zscaler Private Access, Teleport, etc...), a zero-config remote access VPN (i.e. alternative to OpenVPN Access Server, Twingate, Tailscale, etc...), a scalable infrastructure for secure tunnels (i.e. alternative to ngrok), but also as an API gateway, an AI gateway, a secure infrastructure for MCP gateways and A2A architectures, a PaaS-like platform for secure as well as anonymous hosting and deployment for containerized applications, a Kubernetes gateway/ingress/load balancer and even as an infrastructure for your own homelab.

Octelium provides a scalable zero trust architecture (ZTA) for identity-based, application-layer (L7) aware secret-less secure access, via both private client-based access over WireGuard/QUIC tunnels as well as public clientless access (i.e. BeyondCorp), for users, both humans and workloads, to any private/internal resource behind NAT in any environment as well as to publicly protected resources such as SaaS APIs and databases via context-aware access control on a per-request basis through policy-as-code.

I'd like to point out that this is not an MVP, as I said earlier I've been working on this project solely for way too many years now. The status of the project is basically public beta or simply v1.0 with bugs (hopefully nothing too embarrassing). The APIs have been stabilized, the architecture and almost all features have been stabilized too. Basically the only thing that keeps it from being v1.0 is the lack of testing in production (for example, most of my own usage is on Linux machines and containers, as opposed to Windows or Mac) but hopefully that will improve soon. Secondly, Octelium is not a yet another crippled freemium product with an """open source""" label that's designed to force you to buy a separate fully functional SaaS version of it. Octelium has no SaaS offerings nor does it require some paid cloud-based control plane. In other words, Octelium is truly meant for self-hosting. Finally, I am not backed by VC and so far this has been simply a one-man show even though I'd like to believe that I did put enough effort to produce a better overall quality before daring to publicly release it than that of a typical one-man project considering the project's atypical size and nature.

Comments

sybercecurity•4h ago
Wow - looks impressive. Like the direction it's going. Doing things where access policies can be set as code is the way to go IMHO.

One issue I've heard from ZTA early adopters is the lack of interoperability between the various ZTNA solutions. Not a big problem unless you have two organizations that have different solutions that now have to work together (merger, partnership, etc.). Ironically, I have overheard people complain enough that they would pay for a FOSS solution...

geoctl•4h ago
Thank you. Actually one of the very hardest things for me working on Octelium is basically how to describe it concisely and clearly and I still can't say that I have an answer, that's why I prefer to describe it as a "unified secure/zero trust access" platform. It's a ZTNA platform but not in the typical sense, it's also a remote-access VPN but actually works via identity-aware proxies to control access at L-7 instead of at L-3 like in VPNs. It's BeyondCorp but actually supports client-less access for both humans via their browsers and SSO but it also supports client-less access for workloads via OAuth2 client credential flows and standard bearer authentication which makes it relevant for any workload written in any language to access all your HTTP-based Services via a single bearer access token without being aware of the Cluster's existence at all. And it's also a deployment platform that enables you to deploy and scale any containerized application, HTTP-based or not, and instantly provide secure client-based/client-less access to it via your policies or even completely expose it to anonymous access like it's a hosting platform if you wish.

Show HN: Open Evaluation

https://openevaluation.ai/
1•cjcenizal•1m ago•0 comments

Apple to Open AI Models to Developers, Betting That It Will Spur New Apps

https://www.bloomberg.com/news/articles/2025-05-20/apple-to-open-ai-models-to-developers-betting-that-it-will-spur-new-apps
1•spenvo•1m ago•0 comments

Who were the ancient Denisovans? Fossils reveal secrets about mysterious humans

https://www.nature.com/articles/d41586-025-01549-3
1•rbanffy•4m ago•0 comments

Spring AI 1.0 Released, Streamlines AI App Development with Broad Model Support

https://www.infoq.com/news/2025/05/spring-ai-1-0-streamlines-apps/
1•rbanffy•5m ago•0 comments

Show HN: Rocketship – Open-source E2E testing for event-driven systems

https://github.com/rocketship-ai/rocketship
2•magius18•6m ago•0 comments

Show HN: Juvio – UV Kernel for Jupyter

https://github.com/OKUA1/juvio
4•okost1•9m ago•0 comments

Show HN: I build an AI medical scrub for physicians

https://patientnotes.ai
1•vadimk_77•9m ago•0 comments

Perfect Code, No Secrets

https://funnelstory.ai/blog/engineering/perfect-code-no-secrets
2•preetamjinka•12m ago•0 comments

I built a Telegram bot for crypto arbitrage alerts 20 exchanges flexible signals

2•quatro•14m ago•0 comments

Amplification of epidemic spread by individuals exposed to misinformation

https://www.nature.com/articles/s44260-025-00038-y
1•rbanffy•16m ago•0 comments

Pgline – PostgreSQL node.js driver written in TypeScript

https://github.com/stanNthe5/pgline
1•theThree•16m ago•0 comments

LightLab: Controlling Light Sources in Images with Diffusion Models

https://nadmag.github.io/LightLab/
1•billconan•17m ago•0 comments

Robin: A multi-agent system for automating scientific discovery

https://arxiv.org/abs/2505.13400
4•nopinsight•20m ago•0 comments

Show HN: I Launched an Agency Framer Template Celebrating with a Discount

https://www.framer.com/marketplace/templates/kierkegaard/
1•brownieman1325•21m ago•0 comments

Show HN: A browser-based tone generator built with the Web Audio API

https://maketonesonline.com/
2•eddguzzo•21m ago•0 comments

Struggling with what to do with engineering intern

1•pootietangus•21m ago•0 comments

Show HN: prompt-kit, UI components and blocks for building AI apps

https://www.prompt-kit.com/
1•ibelick•21m ago•0 comments

French police launch prison hunt for mini Chinese-made phones

https://www.bbc.com/news/articles/cnv11qvq397o
3•rntn•22m ago•2 comments

Finding Your Next Amusement Park Ride with APIs

https://www.raymondcamden.com/2025/05/15/finding-your-next-amusement-park-ride-with-apis
1•gnabgib•22m ago•0 comments

An Open File Format for storing the information from a forge such as issues, pu

https://f3.forgefriends.org/
1•todsacerdoti•27m ago•0 comments

Verify and find human-made content

https://nonbot.org
1•saikatsg•28m ago•0 comments

Spring AI 1.0 GA Released

https://spring.io/blog/2025/05/20/spring-ai-1-0-GA-released/
1•kreig•28m ago•0 comments

Universal Intelligence v1.0 is out AI made simple

https://github.com/blueraai/universal-intelligence
1•bluera•28m ago•1 comments

Show HN: LLM Inference Requirements Profiler

https://www.open-scheduler.com/
2•benjonr•28m ago•0 comments

Tell HN: Got a dev project? Have my premium .dev domain

1•pavlov•29m ago•0 comments

Show HN: A Lichess-inspired online chess app I built as a junior dev

https://chess-pearl-xi.vercel.app/
1•bberkay•29m ago•0 comments

Installing Consumer-Owned Antennas and Satellite Dishes

https://www.fcc.gov/consumers/guides/installing-consumer-owned-antennas-and-satellite-dishes
1•toomuchtodo•31m ago•3 comments

Show HN: Secria – Private, Secure Email Built for the Quantum Era

2•adrianmav•31m ago•0 comments

Show HN: I built an app that turns code or Swagger into interactive API docs

https://www.docpilot.dev/
1•AnindoNeel•31m ago•0 comments

A Genetic Clue to Why Men Are Taller Than Women

https://www.nytimes.com/2025/05/19/health/height-men-women-genes.html
2•marojejian•34m ago•1 comments