Arrow left and right: switch to the adjacent tool in the overview. Arrow up and down scroll the page.

Warpgate

Warpgate

Open Source

Transparent SSH, HTTPS & database bastion without client software

Visit Website
Hearts Heat (0–100)
7,355 StarsApache-2.0v0.26.1Jul 15, 2026Since Feb 2022195 open issues

AI Summary

Warpgate is an intelligent bastion host that transparently forwards SSH, HTTPS, Kubernetes, MySQL and PostgreSQL connections without requiring special client software. Written in Rust, the tool offers native 2FA and SSO support, full session recording and an integrated admin web interface. Ideal for DevOps teams that need secure, auditable access to infrastructure resources.

Screenshot of Warpgate website

Pros

  • +No additional client software required - completely transparent
  • +Comprehensive session recording with replay function via web UI
  • +Native 2FA and SSO support out-of-the-box
  • +Single binary in 100% safe Rust without dependencies

Cons

  • Requires initial setup configuration and deployment on bastion host
  • Still a relatively young project compared to established enterprise solutions

Use Cases

  • Secure access to servers and databases in the DMZ with full audit trail
  • Session recording and live monitoring of SSH and database connections
  • Centralized access management with 2FA and SSO for Kubernetes clusters
  • Granular permission assignment between users and services without VPN overhead

Who is it for?

DevOps teams and system administrators who need secure, auditable access to infrastructure resources without complex VPN or jump host setups.

Tags

Platform: linux, self-hosted
Pricing: Open Source

What is Warpgate?

Warpgate is a bastion host that transparently proxies SSH, HTTPS, Kubernetes, MySQL and PostgreSQL connections. Clients require no additional software. Anyone connecting via a standard SSH client or browser is automatically routed through Warpgate to the target system. The tool is written in Rust, ships as a single binary with no external dependencies, and includes an admin web interface.

Core features

  • Transparent protocol support for SSH, HTTPS, MySQL, PostgreSQL and Kubernetes, with no client-side configuration.
  • Session recording with replay. All connections are recorded and can be played back through the web UI, including live monitoring of active sessions.
  • Native 2FA and SSO out of the box, with no external plugins or middleware.
  • Granular access control between users and target services, centrally configurable without VPN infrastructure.
  • Single binary in safe Rust with no runtime dependencies, which simplifies deployment and updates.

Who is Warpgate for?

DevOps teams that need auditable server access without deploying a full VPN or commercial jump-host solution. Warpgate is particularly relevant for teams that want to secure database connections in a DMZ: MySQL and PostgreSQL are supported natively, with session recording included.

The initial setup requires a dedicated bastion host and some configuration work. Teams without experience deploying self-hosted services should budget time for this. Warpgate is a comparatively young project, meaning APIs and configuration formats may still change.

Context & alternatives

Warpgate sits in the category of self-hosted bastion-host solutions. Comparable approaches include Teleport (with more enterprise features and correspondingly greater complexity) and Apache Guacamole (browser-based, but without a native SSH proxy of the same kind). Against these projects, Warpgate stands out for its lean deployment and the absence of any client software requirement. For teams specifically looking to audit database connections using a single binary, there are few direct equivalents in the open-source space.

Related Tools

Meooow! Want tool tips by email?

Yes, please!