{"repo":"orion-belt-dev/orion-belt","free":true,"listed":false,"github":"https://github.com/orion-belt-dev/orion-belt","clone":"git clone https://github.com/orion-belt-dev/orion-belt.git","description":"Self-hosted SSH/RDP access gateway with PAM workflows — reverse-tunnel agents, session recording, JIT approvals, and ReBAC. A lighter self-hosted alternative to the big zero-trust access platforms.","language":"Go","stars":42,"topics":["access-control","audit-logging","bastion-host","golang","pam","session-recording","ssh-proxy","zero-trust","privileged-access-management","ssh-proxy-server"],"license":null,"category":"self-hosted-apps","readme_excerpt":"Orion Belt Self-hosted SSH access gateway with PAM workflows. Self-hosted SSH/RDP access gateway with PAM workflows, without opening inbound ports or adopting a large platform. Agents dial out over reverse SSH; you get session recording, live watch, JIT approvals, MFA/WebAuthn, ReBAC, and optional SSH CA. v1.0.0 — stable and public. Free to self-host and use internally under Apache 2.0 + Commons Clause. You cannot sell Orion Belt as a product or hosted service. Details: orion-belt.dev. Why Orion Belt? --- --- ✓ Self-hosted — no SaaS dependency ✓ Reverse SSH agents — no inbound firewall holes on targets ✓ Session recording + live watch ✓ JIT access with approvals (UI / API / ChatOps) ✓ MFA — TOTP + WebAuthn ✓ ReBAC authorization (optional OpenFGA) ✓ Optional SSH Certificate Authority ✓ Linux packages (deb / rpm / apk) Orion Belt in Action Try Orion Belt in 10 minutes Goal: gateway up → agent dials out → SSH works → session recorded. All you need is Docker. One command: it generates its own secrets, starts the gateway, creates your admin user, registers a demo machine ( lab-1 ), and prints a link that signs you in to the console. Then, in the console: 1. Machines → lab-1 → web terminal — run a few commands 2. Sessions → Playback — watch the recording of what you just did Same thing from a terminal, if you prefer: ./bin/osh -c client.yaml root@lab-1 Stop everything with ./scripts/docker-quickstart.sh --down . Full walkthrough, including running an agent on a real machine: Try Or","default_branch":null,"files":null,"tree":[],"storefront":"/r/orion-belt-dev","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/orion-belt-dev/orion-belt/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}