(2)
Envoy Rate Limit Service (ratelimit) is a Go/gRPC service that provides centralized rate limiting for Envoy and other proxies.
5h
100K+
Certificate signing request agent for integrating cert-manager with Istio
5h
100K+
Sealed Secrets is a Kubernetes controller and tool for one-way encrypted Secrets.
11h
100K+
The Kyverno Policy Reporter watches for PolicyReport Resources. It creates Prometheus Metrics and can send rule validation events to different targets like Loki, Elasticsearch, Slack or Discord
5h
100K+
AWS Private CA is an AWS service that can setup and manage private CAs, as well as issue private certificates.
5h
100K+
OpenBao provides a solution to manage, store, and distribute sensitive data, including secrets, certificates, and keys
11h
50K+
This project signs and proxies HTTP requests with Sigv4
5h
50K+
The official image for monitoring systems, containers and applications with Netdata.
4h
500M+
570
Calico CSI driver for secure connections from Kubernetes pods to local daemons.
5h
50K+
An open source, Google Zanzibar-inspired database for fine-grained authorization.
11h
50K+
2
Kubernetes controller that synchronizes Azure Key Vault secrets, certificates, and keys into native Kubernetes Secrets via the AzureKeyVaultSecret CRD.
5h
50K+
Certificate Authority for the Hyperledger Fabric blockchain network
5h
50K+
2
Packages Gatekeeper Custom Resource Definitions and kubectl for deploying OPA-based policy enforcement on Kubernetes.
5h
50K+
A Kubernetes admission controller to integrate container image signature verification and trust pinning into a cluster.
5h
50K+
Kyverno Reports server provides a scalable solution for storing policy reports and cluster policy reports.
5h
50K+
Calico aggregated API server that exposes projectcalico.org APIs through the Kubernetes API aggregation layer.
5h
50K+
DEPRECATED; Notary server and signer cooperatively handle signing and distribution
2y
5M+
72
A container management platform built for organizations that deploy containers in production.
1d
100M+
442
Cloud-native, platform-agnostic, scalable API Gateway with plugin ecosystem for authentication, rate limiting, and observability. Supports REST, GraphQL, gRPC, and WebSocket protocols with DB-less and declarative configuration modes.
5h
50K+
6
Calico Whisker provides a web UI to view network flows in Kubernetes clusters.
5h
50K+
Calico fan-out proxy that scales access to the Calico datastore for large clusters.
5h
50K+
Calico command-line tool (calicoctl) for managing Calico network and security configuration in Kubernetes.
5h
50K+
A trust manager package image that provides Debian CA certificates for use as an init container with cert-manager trust-manager.
11h
50K+
Cloud native Identity & Access Proxy (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s) requests.
11h
50K+
Mounts secrets, keys, and certificates from external stores (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, HashiCorp Vault) into Kubernetes pods as files via the CSI volume API.
11h
50K+
Tool that retrieves and manages SVIDs on behalf of a workload via the SPIFFE Workload API.
11h
50K+