frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Octelium – L7-Aware ZeroTrust Remote Access ZTNA over WireGuard and K8s

https://github.com/octelium/octelium
2•geoctl•5h ago
Hello HN, I've been working solo on Octelium for years now and I'd love to get some honest opinions from you. Octelium is simply an open source, self-hosted, unified platform for zero trust resource access that is primarily meant to be a modern alternative to corporate VPNs and remote access tools. It is built to be generic enough to not only operate as a a zero-config remote access VPN (i.e. alternative to OpenVPN Access Server, Twingate, Tailscale, etc...), ZTNA/BeyondCorp platform (i.e. alternative to Cloudflare Zero Trust, Google BeyondCorp, Zscaler Private Access, Teleport, etc...), a scalable infrastructure for secure tunnels (i.e. alternative to ngrok, Cloudflare Tunnels, etc...), but also can operate as an API gateway, an AI gateway, a secure infrastructure for MCP gateways and A2A architectures, a PaaS-like platform for secure as well as anonymous hosting and deployment for containerized applications, a Kubernetes gateway/ingress/load balancer and even as an infrastructure for your own homelab.

Octelium provides a scalable zero trust architecture (ZTA) for identity-based, application-layer (L7) aware secret-less secure access (eliminating the distribution of L7 credentials such as API keys, SSH and postgres/mysqal-based databases' passwords as well as mTLS certs), via both private client-based access over WireGuard/QUIC tunnels as well as public clientless access, for users, both humans and workloads, to any private/internal resource behind NAT in any environment as well as to publicly protected resources such as SaaS APIs and databases via identity-based, context-aware, L7 aware ABAC on a per-request basis through centralized policy-as-code with CEL and OPA.

You can read more in detail about the features and how octelium works in the documentation https://octelium.com/docs

Comments

znpy•5h ago
This is very interesting.

I love the code being AGPLv3, this means i can actually trust you not to pull the rug from under my feet.

geoctl•4h ago
Thank you. The harsh reality is that I've been undecided on the license for years while working the project (the initial private repo had it all AGPLv3 as opposed to only the Cluster side in this public repo). The reason for choosing it AGPL for Cluster-side/Apache for client-side is that I am basically working on it solo and I have neither the funding nor the press to prove that that my work is the original work of any derivative proprietary work. Also the license issue is very weird to say the least, If I release it fully Apache, it might mean to some that I am probably pulling the rug at some point like many others who did even if I have no intention to do so. If I release it fully AGPL, some might see this as not really true FOSS regardless of the fact that it actually is. It's truly a bizarre situation releasing open source these days with all the bait-and-switch VC-backed "open source" software and all the licensing changes that happened since 2020 for many of the most popular open source projects. Also, I never intended for Octelium to become a SaaS product and the architecture itself proves that. This project is more akin to Kubernetes and cilium (without the funding part!) that the idea of any company self-hosting it in anyway has no conflicts with me since that's what I intended to build in the first place (as opposed to releasing a "demo" FOSS project while forcing you to move to a separate, fully functional SaaS product).

Show HN: Text an AI girlfriend to prepare you for the real thing

https://www.textmatcha.com/
1•Jsuh•54s ago•0 comments

NanoKVM Pro Delivers 4K IP-KVM Capabilities with Dual-System Support

https://linuxgizmos.com/nanokvm-pro-delivers-4k-ip-kvm-capabilities-with-dual-system-support-and-enhanced-remote-management/
1•PixelN0va•1m ago•0 comments

Waterfox Private Search

https://search.waterfox.net/
2•elashri•11m ago•0 comments

An LLM trapped on inferior hardware and infused with existential dread – for art

https://www.xda-developers.com/llm-raspberry-pi-art-piece/
2•toss1•14m ago•0 comments

EVMap: Open-source map for finding EV charging stations

https://ev-map.app/
3•billybuckwheat•19m ago•0 comments

Sudoku-Bench Leaderboard

https://pub.sakana.ai/sudoku/
1•hardmaru•22m ago•0 comments

Texas will require public school classrooms to display Ten Commandments

https://www.texastribune.org/2025/05/24/ten-commandments-texas-schools-senate-bill-10/
3•geox•23m ago•1 comments

The latest image to text and OCR technology

https://vheer.com/image-to-text
1•vertex_steven•24m ago•0 comments

Pennylane – open-source Python framework for quantum programming

https://pennylane.ai/
1•nstj•26m ago•0 comments

Creating issues with Copilot on github.com is in public preview

https://github.blog/changelog/2025-05-19-creating-issues-with-copilot-on-github-com-is-in-public-preview/
1•pabs3•28m ago•0 comments

Effects of Political Advertising on Facebook and Instagram Before 2020 Election

https://www.nber.org/papers/w33818
1•Bostonian•29m ago•0 comments

The islanders facing China's menacing presence on their horizon

https://www.bbc.com/news/articles/cdxkkvw8r4no
1•danielam•30m ago•0 comments

AI Agent Trading Library | FIXParser

https://fixparser.dev/
1•logotype•34m ago•1 comments

Always Do Extra

https://www.bennorthrop.com/Essays/2021/always-do-extra.php
1•MichaelCharles•34m ago•0 comments

Stack overflow is almost dead

https://newsletter.pragmaticengineer.com/p/the-pulse-134
6•spenvo•38m ago•0 comments

Google Is Putting Its Gemini AI into Robots

https://www.cnet.com/tech/computing/google-is-putting-its-gemini-ai-into-robots/
2•Anon84•40m ago•0 comments

Linux 6.15 Released

https://lore.kernel.org/lkml/CAHk-=wiLRW8DN8-4jmeCZH0OpO8skXOC5e6FwMfsPwGMpQYmVQ@mail.gmail.com/T/#u
1•jrepinc•40m ago•1 comments

Furthur – PromptNet (Early Beta Open to HN)

1•nordic_lion•44m ago•0 comments

OpenAI's o3 model sabotaged a shutdown mechanism

https://twitter.com/JeffLadish/status/1926085641789407409
1•Bluestein•45m ago•0 comments

How hardware identifiers work on a PC

https://github.com/vercel/next.js/discussions/79620
1•h89klpop•47m ago•0 comments

There Is No Diffie-Hellman but Elliptic Curve Diffie-Hellman

https://keymaterial.net/2025/05/23/there-is-no-diffie-hellman-but-elliptic-curve-diffie-hellman/
1•aburan28•49m ago•0 comments

What's been your biggest technical bottleneck as a small startup lately?

1•devralcomp•53m ago•0 comments

The Pedestrians Who Abetted a Hawk's Deadly Attack

https://www.theatlantic.com/science/archive/2025/05/hawk-new-jersey-traffic/682913/
1•fortran77•54m ago•0 comments

How MiniDisc Worked

https://obsoletesony.substack.com/p/how-minidisc-worked
3•ecliptik•57m ago•1 comments

Giant Sequoias Are Taking Root in an Unexpected Place: Detroit

https://www.smithsonianmag.com/smart-news/giant-sequoias-are-taking-root-in-an-unexpected-place-detroit-180986557/
1•bookofjoe•58m ago•0 comments

AI and the Death of Literary Criticism

https://quillette.com/2025/05/25/a-the-english-literature-department/
1•sien•58m ago•0 comments

Glaxnimate – Fast and simple vector graphics editor

https://glaxnimate.org
2•josephcsible•1h ago•0 comments

NASA Sets Coverage for 32nd SpaceX Resupply Mission Departure

https://www.nasa.gov/news-release/nasa-sets-coverage-for-32nd-spacex-resupply-mission-departure/
1•MarcoDewey•1h ago•0 comments

AI compliance writer – automate compliance workflow up to 80%

https://tm-report-writer.streamlit.app
1•sauravrandom•1h ago•2 comments

SaaS for Custom Classification Models

1•santanaforai•1h ago•0 comments