Open Source Security
Security tooling has an awkward demand the rest of software does not: you have to trust the thing watching your systems as much as the systems themselves, because a scanner or monitor sees everything sensitive it touches. The open source tools here let you read what they actually do with that access, run them entirely inside your own environment, and keep the scan results, keys, and incident data from ever leaving it.

Headscale
Self-hosted implementation of the Tailscale control server for a single WireGuard-based tailnet

sqlmap
Open-source tool that automates SQL injection detection, exploitation, and database takeover

Trivy
All-in-one security scanner for containers, code, and Kubernetes

Keycloak
Open source identity and access management for adding authentication, user federation, and authorization

JumpServer
Open-source PAM and bastion host for browser access to SSH, RDP, Kubernetes, database, and RemoteApp endpoints
Algo VPN
Ansible-based personal VPN setup for WireGuard and IPsec in the cloud

Nuclei
Fast YAML-based vulnerability scanner for applications, APIs, networks, DNS, and cloud configs

Harbor
Cloud native registry for storing, signing, scanning, and replicating container images and Helm charts

Authelia
Open-source SSO and multi-factor authentication portal for applications behind reverse proxies