Warpgate

Open-source clientless bastion for SSH, HTTPS, RDP, VNC, Kubernetes and databases

ToolPrivileged Access ManagementOpen SourceSelf-hosted

Reviewed by the CyberSecTool editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is Warpgate?

Warpgate is a self-hosted bastion and privileged access gateway that proxies SSH, HTTPS, Kubernetes, MySQL, PostgreSQL, RDP and VNC connections to internal targets. Users connect with their normal clients or through a browser-based terminal and desktop client, so no agent or SSH wrapper is installed on the client side. It ships as a single binary or a Docker image, keeps state in a database, and provides an admin web UI for managing targets, users, roles and session replay. RDP and VNC target support arrived in v0.27.0, published on 1 August 2026.

Best for: Teams that want a self-hosted, audited access gateway across mixed SSH, database, Kubernetes and remote desktop targets without installing client-side software.
Pros
  • Apache-2.0 licensed with no paid tier; the GitHub repository records 7,446 stars, 323 forks and releases through v0.27.2 on 3 August 2026, which indicates ongoing maintenance
  • No client-side software is required: an independent setup guide states it forwards connections straight to the target rather than acting as a jump host
  • One gateway covers interactive shells, Kubernetes, databases and, since v0.27.0, recorded RDP and VNC desktop sessions
  • Deploys as a single binary or Docker image, with clustering and S3 recording storage documented for multi-node setups

Key Features

Target support for SSH, HTTPS, Kubernetes, MySQL, PostgreSQL, RDP and VNC
Browser-based terminal and remote desktop client, alongside connections from native clients
Session recording with live viewing and replay in the admin web UI, including screen and input recording for RDP and VNC
OpenID Connect SSO and TOTP two-factor authentication, plus SSH key authentication
Brute-force protection with IP blocking and user lockout
Multi-node clustering behind a non-sticky load balancer with a shared database
S3-compatible storage for session recordings
Reauthentication policy for critical endpoints such as the web terminal, web desktop and ticket creation

Are you Warpgate? Improve this listing with screenshots, case studies and more.