tlsgate
A fingerprint-gating proxy for TLS services. It filters opportunistic scanner noise using JA3 or JA4 while leaving real authentication to the backend.
Small tools shaped by real infrastructure problems, with an emphasis on understandable security boundaries and straightforward operations. Browse all repositories on GitHub.
A fingerprint-gating proxy for TLS services. It filters opportunistic scanner noise using JA3 or JA4 while leaving real authentication to the backend.
A companion fingerprint-gating proxy for SSH. It reads the plaintext key exchange and uses a HASSH-style fingerprint to reduce background noise.
The shared control plane for tlsgate and sshgate, with centralized fingerprint observations, approval policy, and narrowly scoped node synchronization.
The reusable node-side spine of the fingerprint gates: SQLite state, control-plane sync, rate limits, connection caps, and graceful process lifecycle.
An availability monitor that corroborates failures from independent vantage points and alerts only when a quorum agrees that a service is down.
A compact CoreDNS operations stack for authoritative zones, authenticated replication, managed blocking, APIs, an OIDC console, and monitoring.
A self-hosted inbox for rich operational notifications, with structured cards, actions, Web Push, and Mattermost and Slack compatibility.
A small, standard-library Go client for publishing native Tintwire cards, with bounded retries and selective Mattermost delivery failover.
A focused OpenID Connect relying-party helper for Go web apps, covering the browser flow while leaving session ownership to the application.
A self-hosted MCP memory service that gives AI coding agents durable, scoped recall using PostgreSQL, pgvector, and local Ollama embeddings.
A self-hosted artifact plane for publishing, reviewing, versioning, and sharing interactive web output from AI agents, CI jobs, CLIs, and people.