{"repo":"DiegoGuidaF/PulseWeaver","free":true,"listed":false,"github":"https://github.com/DiegoGuidaF/PulseWeaver","clone":"git clone https://github.com/DiegoGuidaF/PulseWeaver.git","description":"Self-hosted forward-auth sidecar that gates your services by request IP + host — give family and friends per-user access without touching the apps behind your reverse proxy. Not authentication; a roaming-IP heartbeat keeps access current.","language":"TypeScript","stars":46,"topics":["access-control","authorization","caddy","forward-auth","go","golang","homelab","nginx","reverse-proxy","security"],"license":"AGPL-3.0","category":"self-hosted-apps","readme_excerpt":"PulseWeaver is a self-hosted closed-door access layer for reverse proxies: unknown IPs are stopped before they reach your apps, while known devices get per-user access to only the services you grant. It keeps an up-to-date registry of your devices' current IP addresses and answers one question for your reverse proxy on every incoming request: may this client reach this host? Each user gets an explicit allowlist of services; everything else is denied. No config-file reloads, no static IP lists, and no identity provider bolted onto apps that can't handle one. [!NOTE] PulseWeaver is not an authentication system. It never verifies who sends a request; it checks whether the request's IP belongs to a registered device (or trusted network range) and whether that device's owner is allowed to reach the requested host. Want to see the allow/deny model before touching your proxy? Try it locally in a few minutes. Quick links: is this for you? · trial · deployment · security model · troubleshooting Is this for you? PulseWeaver fits best when you run a small self-hosted environment for people you already know: a household, club, friend group, small team, office, or community. Instead of leaving every app's login page reachable by the internet, it keeps the door closed by default and lets known devices in when their current IP is active and their owner has a grant. It is a different posture from Authelia, authentik, or a mesh VPN, not a weaker copy of them: If you already use... PulseWeaver","default_branch":null,"files":null,"tree":[],"storefront":"/r/DiegoGuidaF","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DiegoGuidaF/PulseWeaver/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}