
Teleport
Identity-native infrastructure access for SSH, Kubernetes, RDP and DBs

Teleport is an identity-native access platform that unifies secure access to infrastructure (SSH), Kubernetes, databases, web apps, and desktops through a single control plane. It focuses on eliminating long-lived credentials by using short-lived certificates and strong identity, while providing centralized visibility and audit trails.
Key Features
- Unified access proxy for SSH, Kubernetes, databases, Windows desktops (RDP), and internal web apps
- Short-lived, automatically issued certificates (no shared SSH keys) and session-based access
- Built-in audit logging and session recording/playback (SSH and Kubernetes activity; RDP recording in supported editions)
- Role-based access control (RBAC) with fine-grained policies and access workflows
- Single sign-on integrations (e.g., SAML/OIDC providers) and device-aware access options
- Infrastructure discovery and inventory (nodes, clusters, apps, databases) with a central web UI and CLI (
tsh) - High availability and clustering for running Teleport at scale
Use Cases
- Replace bastion hosts and shared SSH keys with centralized, identity-based SSH access
- Provide secure, auditable Kubernetes access for platform and developer teams
- Centralize database access with consistent authentication, authorization, and auditing
Limitations and Considerations
- Some capabilities (notably certain enterprise features such as advanced access workflows/recording options) may require paid editions depending on your needs
- Operational complexity can be higher than simple SSH bastions due to certificate-based architecture and multi-component deployment
Teleport is well-suited for organizations that want consistent authentication and auditing across multiple infrastructure access methods. It provides a single access plane that scales from small teams to multi-cluster environments while improving credential hygiene and traceability.
Categories:
Tags:
Tech Stack:
Similar Services

Bitwarden
Open-source password manager for individuals and teams
Self-hostable password manager with end-to-end encryption, vault sharing, TOTP, passkeys, and cross-platform apps plus browser extensions.


Documenso
Open-source document signing and workflow platform
Self-hosted platform for preparing, sending, and tracking legally binding e-signatures with templates, audit trails, and team workflows.


SFTPGo
Secure, multi-protocol file transfer server with a web admin UI
Self-hosted SFTP/FTP/WebDAV server with web admin, virtual users, storage backends, and auditing for secure file exchange and managed file transfer workflows.


Sandstorm
Personal cloud to run web apps securely, per-user sandboxed
Self-hosted platform for running web apps with per-user sandboxes, easy install, app store packaging, and sharing via secure links and access controls.


Warpgate
Smart SSH bastion with web UI, RBAC, and audit logs
Self-hosted SSH bastion and access gateway with web UI, RBAC, just-in-time access, session recording, and audit logging for servers and infrastructure.

MeshCentral
Open-source remote device management and remote access server
Web-based remote management server for computers and IoT devices with remote desktop/terminal, file transfer, user/device groups, and auditing.

TLS
TypeScript
JavaScript