Open Source Cloudflare Tunnel Alternative for Developers, Teams and Enterprises
Secure Access to all your Internal Resources
A Complete, Scalable, Self-Hosted, Secure Remote Access Solution for to Access any Internal Resource of any Type Running behind NAT Anywhere including Your Laptop, Private Clouds, IoT and Containers
Zero Trust Secure Access, and Public Anonymous Access too
A Unified Architecture to Provide Identity-aware, Context-based, L7-aware Zero Trust Access for Humans via their Browsers and Workloads via OAuth2 and Bearer Authentication to your Resources as well as Public Anonymous Access that can be used for Hosting and Testing your Web Apps and APIs
A Platform for Deployment, not just Access
A PaaS-like Platform to Seamlessly Deploy, Scale and Provide Secure as well as Public Anonymous Access your Dockerized Applications such as APIs and Web Applications Hosted on Public or Private Container Registries
Integrate with OpenID Connect and SAML SSO Identity Providers
Seamlessly integrate any OpenID Connect or SAML 2.0 SSO Provider (IdP) as well as GitHub OAuth2 and Provide Secure Access to all your Resources for your Teams at Scale. Force Strong MFA via FIDO2 Phishing Resistant Authenticators into Access Control to Sensitive Resources.
Identity-based, L7-aware Access Control
Application-layer Aware Access Control via Identity-based Context-aware ABAC and Policy-as-Code via CEL and Open Policy Agent (OPA)
Client-based as well as Client-less Secure Access
A Unified Zero Trust Architecture that Supports both the Private VPN-like Client-based Mode over WireGuard/QUIC Tunnels as well as the Client-less Public BeyondCorp Mode via Browsers.
Secretless Access to SSH, APIs and Databases
Provide Secretless Access to SSH Servers, HTTP-based APIs, Databases and mTLS-based Applications without the need for Sharing and Distributing L7 Credentials to Users
Scalable Identity Management and Access for Workloads
Unified, Stable Access for your Workloads written in any Programming Language to all your HTTP-based Resources via Standard OAuth2 Client-Credentials Flow and Bearer Authentication without having to use Special SDKs
OpenTelemetry-native Real-time Visibility
OpenTelemetry-ready Layer-7 Aware, Real-Time Visibility and Auditing to Your Log Management and SIEM Providers
Centralized, Declarative and Programmable Management
Designed to be Administered like Kubernetes via DevOps/GitOps-friendly Centralized and Declarative Way. The Cluster is furthermore fully Programmable over gRPC.
© 2025 octelium.comOctelium Labs, LLCAll rights reserved
Octelium and Octelium logo are trademarks of Octelium Labs, LLC.
WireGuard is a registered trademark of Jason A. Donenfeld