Smart SSH, HTTPS and MySQL bastion that needs no client-side software
Find a file
Eugene Pankov 087b943372
lint
2022-08-06 01:01:44 +02:00
.cargo import 2022-04-10 22:58:58 +02:00
.github Update dependabot.yml 2022-07-03 11:33:23 +02:00
docker Updated Dockerfile & setup 2022-07-05 21:32:05 +02:00
warpgate fixed #5 - Automatically kill sessions after access is revoked after config reload 2022-08-05 20:54:37 +02:00
warpgate-admin bumped russh for AES-CTR, DH and HMAC support - fixes #232, fixes #186 2022-08-05 01:36:38 +02:00
warpgate-common lint 2022-08-06 01:01:44 +02:00
warpgate-database-protocols Bump bytes from 1.2.0 to 1.2.1 2022-08-02 13:38:19 +02:00
warpgate-db-entities Bump version: 0.3.0 → 0.4.0 2022-07-27 00:18:03 +02:00
warpgate-db-migrations Bump version: 0.3.0 → 0.4.0 2022-07-27 00:18:03 +02:00
warpgate-protocol-http test driven fixes 2022-08-06 00:55:30 +02:00
warpgate-protocol-mysql test driven fixes 2022-08-06 00:55:30 +02:00
warpgate-protocol-ssh lint 2022-08-06 01:01:44 +02:00
warpgate-sso OIDC login support (#222) 2022-08-05 20:04:40 +02:00
warpgate-web test driven fixes 2022-08-06 00:55:30 +02:00
.all-contributorsrc Add @apiening as a contributor 2022-04-12 18:58:50 +02:00
.bumpversion.cfg OIDC login support (#222) 2022-08-05 20:04:40 +02:00
.dockerignore Updated Dockerfile & setup 2022-07-05 21:32:05 +02:00
.env import 2022-04-10 22:58:58 +02:00
.gitignore import 2022-04-10 22:58:58 +02:00
Cargo.lock OIDC login support (#222) 2022-08-05 20:04:40 +02:00
Cargo.toml OIDC login support (#222) 2022-08-05 20:04:40 +02:00
clippy.toml added cranky and removed all .unwrap() usages 2022-07-23 21:31:35 +02:00
Cranky.toml deny clippy::indexing_slicing 2022-07-23 21:53:21 +02:00
Cross.toml build against older glibc - fixes #33 2022-05-18 01:13:25 -07:00
deny.toml Revert "use workspace-level dependencies" 2022-07-06 09:24:06 +02:00
justfile OIDC login support (#222) 2022-08-05 20:04:40 +02:00
LICENSE Update LICENSE 2022-04-14 11:14:56 +02:00
README.md OIDC login support (#222) 2022-08-05 20:04:40 +02:00
rust-toolchain.toml added cranky and removed all .unwrap() usages 2022-07-23 21:31:35 +02:00
rustfmt.toml sorted imports 2022-07-15 20:27:33 +02:00



GitHub All Releases    


Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps.

  • Set it up in your DMZ, add user accounts and easily assign them to specific hosts and URLs within the network.
  • Warpgate will record every session for you to view (live) and replay later through a built-in admin web UI.
  • Not a jump host - forwards your connections straight to the target instead.
  • Native 2FA and SSO support
  • Single binary with no dependencies.
  • Written in 100% safe Rust.

Getting started & downloads

image
image image

Project Status

The project is currently in alpha stage and is gathering community feedback. See the official roadmap for the upcoming features.

In particular, we're working on:

  • Requesting admin approvals for sessions
  • Support for tunneling PostgreSQL connections,
  • and much more.

How it works

Warpgate is a service that you deploy on the bastion/DMZ host, which will accept SSH, HTTPS and MySQL connections and provide an (optional) web admin UI.

Run warpgate setup to interactively generate a config file, including port bindings. See Getting started for details.

It receives connections with specifically formatted credentials, authenticates the user locally, connects to the target itself, and then connects both parties together while (optionally) recording the session.

When connecting through HTTPS, Warpgate presents a selection of available targets, and will then proxy all traffic in a session to the selected target. You can switch between targets at any time.

You manage the target and user lists and assign them to each other through a config file (default: /etc/warpgate.yaml), and the session history is stored in an SQLite database (default: in /var/lib/warpgate).

You can use the admin web interface to view the live session list, review session recordings, logs and more.

Contributing / building from source

  • You'll need Rust, NodeJS and Yarn
  • Clone the repo
  • Just is used to run tasks - install it: cargo install just
  • Install the admin UI deps: just yarn
  • Build the frontend: just yarn build
  • Build Warpgate: cargo build (optionally --release)

The binary is in target/{debug|release}.

Tech stack

  • Rust 🦀
    • HTTP: poem-web
    • Database: SQLite via sea-orm + sqlx
    • SSH: russh
  • Typescript
    • Svelte
    • Bootstrap

Contributors

Thanks goes to these wonderful people (emoji key):


Eugeny

💻

Spencer Heywood

💻

Andreas Piening

💻

This project follows the all-contributors specification. Contributions of any kind welcome!