19 best security & infrastructure GitHub repos to use
What keeps the rest of it running and safe. Secrets scanning, DNS filtering, deployment, containers and the plumbing you only notice when it breaks.
Find GitHub repos worth using by topic, language, license and how active they are. Navid's picks come first, and each one opens its own page.
This is a list of the best security & infrastructure GitHub repos.
In fact, it has 19 of them, with Navid's picks first.
So if you want security & infrastructure GitHub repos worth your time, you'll love this list.
What keeps the rest of it running and safe. Secrets scanning, DNS filtering, deployment, containers and the plumbing you only notice when it breaks.
Here's what's inside:
- Daytona by daytonaio
- Container by apple
- Vault by hashicorp
- CloakBrowser by CloakHQ
- Infisical by infisical
- Trufflehog by trufflesecurity
- Authentik by goauthentik
- Argo Cd by argoproj
- Spiderfoot by smicallef
- Neko by m1k1o
- Supertokens Core by supertokens
- Crowdsec by crowdsecurity
- Semaphore by semaphoreui
- Easytier by EasyTier
- Gatus by TwiN
- Camofox Browser by jo-inc
- Certimate by certimate-go
- Actions Runner Controller by actions
- Kueue by kubernetes-sigs
Each one comes with what it covers and who it's for.
What are the best security & infrastructure GitHub repos?
Here's the list at a glance.
- Owner
- daytonaio
- Stars
- ★ 72k
- Owner
- apple
- Stars
- ★ 50k
- Owner
- hashicorp
- Stars
- ★ 36k
- Owner
- CloakHQ
- Stars
- ★ 32k
- Owner
- infisical
- Stars
- ★ 29k
- Owner
- trufflesecurity
- Stars
- ★ 28k
- Owner
- goauthentik
- Stars
- ★ 26k
- Owner
- argoproj
- Stars
- ★ 24k
- Owner
- smicallef
- Stars
- ★ 23k
- Owner
- m1k1o
- Stars
- ★ 22k
- Owner
- supertokens
- Stars
- ★ 15k
- Owner
- crowdsecurity
- Stars
- ★ 15k
- Owner
- semaphoreui
- Stars
- ★ 14k
- Owner
- EasyTier
- Stars
- ★ 14k
- Owner
- TwiN
- Stars
- ★ 12k
- Owner
- jo-inc
- Stars
- ★ 11k
- Owner
- certimate-go
- Stars
- ★ 9.3k
- Owner
- actions
- Stars
- ★ 6.5k
- Owner
- kubernetes-sigs
- Stars
- ★ 3k
Top 19 security & infrastructure GitHub repos
1. Daytona by daytonaio
As of June 2026, Daytona's core development has moved to a private codebase. This repository will receive no further updates, fixes, or releases. It remains public and free to use, fork, and build on under the LICENSE, as is and without support or warranty.
Secure and Elastic Infrastructure for Running Your AI-Generated Code.
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Our open-source platform provides sandboxes, full composable computers with complete isolation, a dedicated kernel, filesystem, network stack, and allocated vCPU, RAM, and disk.
Stars: 72k
Install:
bash pip install daytona
View Daytona on GitHub · More about Daytona
2. Container by apple
container is a tool that you can use to create and run Linux containers as lightweight virtual machines on your Mac. It's written in Swift, and optimized for Apple silicon.
The tool consumes and produces OCI-compatible container images, so you can pull and run images from any standard container registry. You can push images that you build to those registries as well, and run the images in any other OCI-compatible application.
container uses the Containerization Swift package for low-level container, image, and process management.
Stars: 50k
Language: Swift
License: Apache-2.0
View Container on GitHub · More about Container
3. Vault by hashicorp
Please note: We take Vault's security and our users' trust very seriously. If you believe you have found a security issue in Vault, please responsibly disclose by contacting us at security@hashicorp.com.
Vault is a tool for securely accessing secrets. A secret is anything that you want to tightly control access to, such as API keys, passwords, certificates, and more. Vault provides a unified interface to any secret, while providing tight access control and recording a detailed audit log.
A modern system requires access to a multitude of secrets: database credentials, API keys for external services, credentials for service-oriented architecture communication, etc. Understanding who is accessing what secrets is already very difficult and platform-specific. Adding on key rolling, secure storage, and detailed audit logs is almost impossible without a custom solution. This is where Vault steps in.
Stars: 36k
Language: Go
License: Other
View Vault on GitHub · More about Vault
4. CloakBrowser by CloakHQ
Not a patched config. Not a JS injection. A real Chromium binary with fingerprints modified at the C++ source level. Antibot systems score it as a normal browser, because it is a normal browser.
Drop-in Playwright/Puppeteer replacement for Python and JavaScript. Same API, same code, just swap the import. 3 lines of code, 30 seconds to unblock. 71 source-level C++ patches, canvas, WebGL, audio, fonts, GPU, screen, WebRTC, network timing, automation signals, CDP input behavior humanize=True, human-like mouse curves, keyboard timing, and scroll patterns. One flag, behavioral detection passes Pro: 0.9 reCAPTCHA v3 score, human-level, server-verified Passes Cloudflare Turnstile, FingerprintJS, BrowserScan, tested against 30+ detection sites Auto-downloads the right binary, free or Pro based on your license pip install cloakbrowser or npm install cloakbrowser, binary auto-downloads, zero config Latest binary, free to try, sign in with GitHub, point the newest build at your hardest target, scale to thousands of sessions on Pro
See Troubleshooting for site-specific issues (FingerprintJS, Kasada, reCAPTCHA).
Stars: 32k
Language: Python
License: MIT
Install:
bash pip install cloakbrowser
View CloakBrowser on GitHub · More about CloakBrowser
5. Infisical by infisical
The open-source secret management platform: Sync secrets/configs across your team/infrastructure and prevent secret leaks.
Infisical is the open source security infrastructure platform that teams use for secrets, certificates, and privileged access management.
We're on a mission to make security tooling more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.
Stars: 29k
Language: TypeScript
License: Other
View Infisical on GitHub · More about Infisical
6. Trufflehog by trufflesecurity
To learn more about TruffleHog and its features and capabilities, visit our product page.
Are you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials? We have an enterprise product that can help! Learn more at.
We take the revenue from the enterprise product to fund more awesome open source projects that the whole community can benefit from.
Stars: 28k
Language: Go
License: AGPL-3.0
Install:
bash brew install trufflehog
View Trufflehog on GitHub · More about Trufflehog
7. Authentik by goauthentik
authentik is an open-source Identity Provider (IdP) for modern SSO. It supports SAML, OAuth2/OIDC, LDAP, RADIUS, and more, designed for self-hosting from small labs to large production clusters.
Our enterprise offering is available for organizations to securely replace existing IdPs such as Okta, Auth0, Entra ID, and Ping Identity for robust, large-scale identity management. Docker Compose: recommended for small/test setups. See the documentation. Kubernetes (Helm Chart): recommended for larger setups. See the documentation and the Helm chart repository. AWS CloudFormation: deploy on AWS using our official templates. See the documentation. DigitalOcean Marketplace: one-click deployment via the official Marketplace app. See the app listing.
See the Developer Documentation for information about setting up local build environments, testing your contributions, and our contribution process.
Stars: 26k
Language: Python
License: Other
View Authentik on GitHub · More about Authentik
8. Argo Cd by argoproj
Argo CD is a declarative GitOps continuous delivery tool for Kubernetes.
- Application definitions, configurations, and environments should be declarative and version controlled. 1. Application deployment and lifecycle management should be automated, auditable, and easy to understand.
To learn more about Argo CD go to the complete documentation. Check live demo at https://cd.apps.argoproj.io/.
Stars: 24k
Language: Go
License: Apache-2.0
View Argo Cd on GitHub · More about Argo Cd
9. Spiderfoot by smicallef
SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.
SpiderFoot has an embedded web-server for providing a clean and intuitive web-based interface but can also be used completely via the command-line. It's written in Python 3 and MIT-licensed. Web based UI or CLI Over 200 modules (see below) Python 3.7+ YAML-configurable correlation engine with 37 pre-defined rules CSV/JSON/GEXF export API key export/import SQLite back-end for custom querying Highly configurable Fully documented Visualisations TOR integration for dark web searching Dockerfile for Docker-based deployments Can call other tools like DNSTwist, Whatweb, Nmap and CMSeeK Actively developed since 2012!
Need more from SpiderFoot? Check out SpiderFoot HX for: 100% Cloud-based and managed for you Attack Surface Monitoring with change notifications by email, REST and Slack Multiple targets per scan Multi-user collaboration Authenticated and 2FA Investigations Customer support Third party tools pre-installed & configured Drive it with a fully RESTful API TOR integration built-in Screenshotting Bring your own Python SpiderFoot modules Feed scan data to Splunk, ElasticSearch and REST endpoints
Stars: 23k
Language: Python
License: MIT
Install:
bash wget https://github.com/smicallef/spiderfoot/archive/v4.0.tar.gz
View Spiderfoot on GitHub · More about Spiderfoot
10. Neko by m1k1o
Welcome to Neko, a self-hosted virtual browser that runs in Docker and uses WebRTC technology. Neko is a powerful tool that allows you to run a fully-functional browser in a virtual environment, giving you the ability to access the internet securely and privately from anywhere. With Neko, you can browse the web, run applications, and perform other tasks just as you would on a regular browser, all within a secure and isolated environment. Whether you are a developer looking to test web applications, a privacy-conscious user seeking a secure browsing experience, or simply someone who wants to take advantage of the convenience and flexibility of a virtual browser, Neko is the perfect solution.
In addition to its security and privacy features, Neko offers the ability for multiple users to access it simultaneously. This makes it an ideal solution for teams or organizations that need to share access to a browser, as well as for individuals who want to use multiple devices to access the same virtual environment. With Neko, you can easily and securely share access to a browser with others, without having to worry about maintaining separate configurations or settings. Whether you need to collaborate on a project, access shared resources, or simply want to share access to a browser with friends or family, Neko makes it easy to do so.
Neko is also a great tool for hosting watch parties and interactive presentations. With its virtual browser capabilities, Neko allows you to host watch parties and presentations that are accessible from anywhere, without the need for in-person gatherings. This makes it easy to stay connected with friends and colleagues, even when you are unable to meet in person. With Neko, you can easily host a watch party or give an interactive presentation, whether it's for leisure or work. Simply invite your guests to join the virtual environment, and you can share the screen and interact with them in real-time.
Stars: 22k
Language: Go
License: Apache-2.0
View Neko on GitHub · More about Neko
11. Supertokens Core by supertokens
Add secure login and session management to your apps. SDKs available for popular languages and front-end frameworks e.g. Node.js, Go, Python, React.js, React Native, Vanilla JS, etc.
- Frontend SDK: Manages session tokens and renders login UI widgets 2. Backend SDK: Provides APIs for sign-up, sign-in, signout, session refreshing, etc. Your Frontend will talk to these APIs 3. SuperTokens Core: The HTTP service for the core auth logic and database operations. This service is used by the Backend SDK
[](https://supertokens.com/docs/guides) Passwordless Login Social Login Email Password Login Phone Password Login Session Management Multi-Factor Authentication Multi Tenancy / Organization Support (Enterprise SSO) User Roles Microservice Authentication What is SuperTokens? Philosophy Features + Demo app Documentation Architecture Why Java? ⌨ User Management Dashboard SuperTokens vs Others Building from source Community Contributors Contributing License
Stars: 15k
Language: Java
License: Other
View Supertokens Core on GitHub · More about Supertokens Core
12. Crowdsec by crowdsecurity
CrowdSec is an open-source and participative security solution offering crowdsourced server detection and protection against malicious IPs. Detect and block with our Security Engine, contribute to the network, and enjoy our real-time community blocklist.
It detects bad behaviors by analyzing log sources and HTTP requests, and allows active remediation thanks to the Remediation Components.
The "Community Blocklist" is a curated list of IP addresses identified as malicious by CrowdSec. The Security Engine proactively blocks the IP addresses of this blocklist, preventing malevolent IPs from reaching your systems.
Stars: 15k
Language: Go
License: MIT
View Crowdsec on GitHub · More about Crowdsec
13. Semaphore by semaphoreui
Modern UI for Ansible, Terraform/OpenTofu/Terragrunt, PowerShell and other DevOps tools.
If your project has grown and deploying from the terminal is no longer feasible, then Semaphore UI is the tool you need.
Semaphore UI is a modern web interface for managing popular DevOps tools.
Stars: 14k
Language: Go
License: MIT
Install:
bash docker run -p 3000:3000 --name semaphore \
View Semaphore on GitHub · More about Semaphore
14. Easytier by EasyTier
EasyTier supports quick networking using shared public nodes. When you don't have a public IP, you can use the free shared nodes provided by the EasyTier community. Nodes will automatically attempt NAT traversal and establish P2P connections. When P2P fails, data will be relayed through shared nodes.
When using shared nodes, each node entering the network needs to provide the same --network-name and --network-secret parameters as the unique identifier of the network.
Note: If you cannot ping through, it may be that the firewall is blocking incoming traffic. Please turn off the firewall or add allow rules.
Stars: 14k
Language: Rust
License: LGPL-3.0
Install:
bash brew tap brewforge/chinese
View Easytier on GitHub · More about Easytier
15. Gatus by TwiN
Gatus is a developer-oriented health dashboard that gives you the ability to monitor your services using HTTP, ICMP, TCP, and even DNS queries as well as evaluate the result of said queries by using a list of conditions on values like the status code, the response time, the certificate expiration, the body and many others. The icing on top is that each of these health checks can be paired with alerting via Slack, Teams, PagerDuty, Discord, Twilio and many more.
I personally deploy it in my Kubernetes cluster and let it monitor the status of my core applications: https://status.twin.sh/
Have any feedback or questions? Create a discussion. Table of Contents Why Gatus? Features Usage Configuration Endpoints External Endpoints Suites (ALPHA) Conditions Placeholders Functions Web UI Announcements Storage Client configuration Tunneling Alerting Configuring AWS SES alerts Configuring ClickUp alerts Configuring Datadog alerts Configuring Discord alerts Configuring Email alerts Configuring Gitea alerts Configuring GitHub alerts Configuring GitLab alerts Configuring Google Chat alerts Configuring Gotify alerts Configuring HomeAssistant alerts Configuring IFTTT alerts Configuring Ilert alerts Configuring Incident.io alerts Configuring Line alerts Configuring Matrix alerts Configuring Mattermost alerts Configuring Messagebird alerts Configuring n8n alerts Configuring New Relic alerts Configuring Ntfy alerts Configuring Opsgenie alerts Configuring PagerDuty alerts Configuring Plivo alerts Configuring Pushover alerts Configuring Rocket.Chat alerts Configuring SendGrid alerts Configuring Signal alerts Configuring SIGNL4 alerts Configuring Slack alerts Configuring Splunk alerts Configuring Squadcast alerts Configuring Teams alerts (Deprecated) Configuring Teams Workflow alerts Configuring Telegram alerts Configuring Twilio alerts Configuring Vonage alerts Configuring Webex alerts Configuring Zapier alerts Configuring Zulip alerts Configuring custom alerts Setting a default alert Maintenance Security Basic Authentication OIDC TLS Encryption Metrics Custom Labels Connectivity Remote instances (EXPERIMENTAL) Deployment Docker Helm Chart Terraform Kubernetes Running the tests Using in Production FAQ Sending a GraphQL request Recommended interval Default timeouts Monitoring a TCP endpoint Monitoring a UDP endpoint Monitoring a SCTP endpoint Monitoring a WebSocket endpoint Monitoring an endpoint using gRPC Monitoring an endpoint using ICMP Monitoring an endpoint using DNS queries Monitoring an endpoint using SSH Monitoring an endpoint using STARTTLS Monitoring an endpoint using TLS Monitoring domain expiration Concurrency Reloading configuration on the fly Endpoint groups How do I sort by group by default? Exposing Gatus on a custom path Exposing Gatus on a custom port Use environment variables in config files Configuring a startup delay Keeping your configuration small Proxy client configuration How to fix 431 Request Header Fields Too Large error Badges Uptime Health Health (Shields.io) Response time Response time (chart) How to change the color thresholds of the response time badge API Interacting with the API programmatically Raw Data Uptime Response Time Installing as binary High level design overview
Stars: 12k
Language: Go
License: Apache-2.0
Install:
bash docker run -p 8080:8080 --name gatus ghcr.io/twin/gatus:stable
View Gatus on GitHub · More about Gatus
16. Camofox Browser by jo-inc
Standing on the mighty shoulders of Camoufox - a Firefox fork with fingerprint spoofing at the C++ level.
Built by the team behind jo, a personal AI agent that runs half on your Mac, half on a dedicated cloud machine just for you, with zero maintenance needed. Available on macOS, Telegram, WhatsApp, and email. Try the beta free -
AI agents need to browse the real web. Playwright gets blocked. Headless Chrome gets fingerprinted. Stealth plugins become the fingerprint.
Stars: 11k
Language: JavaScript
License: MIT
Install:
bash git clone https://github.com/jo-inc/camofox-browser && cd camofox-browser
View Camofox Browser on GitHub · More about Camofox Browser
17. Certimate by certimate-go
An open-source and free self-hosted SSL certificates ACME tool, automates the full-cycle of issuance, deployment, renewal, and monitoring visually. Self-hosted: Private deployment. All data is stored locally, to ensure data privacy and security. Cross Platforms: Compatible with various operating systems, including Windows/Linux/macOS. Zero Dependencies: No need to install databases, runtimes, or any frameworks. Ready to use out of the box. Low Resource Usage: Extremely lightweight, requiring only ~16 MB of memory. Easy to Use: Automates certificate management with a visual workflow, all with just a few simple configurations. Flexible workflow orchestration, fully automation from certificate application to deployment. Supports requesting single/multiple/wildcard domain certificates, IP address certificates, with options for RSA or ECC key. Supports DNS-01 challenge and HTTP-01 challenge both. Supports various certificate formats such as PEM, PFX, JKS. Supports more than 70+ domain registrars (e.g., AWS, Cloudflare, GoDaddy, Alibaba Cloud, Tencent Cloud, etc. Check out full providers). Supports more than 150+ deployment destinations (e.g., Kubernetes, CDN, WAF, load balancers, etc. Check out full providers). Supports multiple notification channels including email, Discord, Slack, Telegram, DingTalk, Feishu, WeCom, and more. Supports multiple ACME CAs including Let's Encrypt, Actalis, Google Trust Services, SSL.com, ZeroSSL, and more. More features waiting to be discovered.
Default administrator account: Username: admin@certimate.fun Password: 1234567890
Work with Certimate right now. Or read other content in the documentation to learn more.
Stars: 9.3k
Language: Go
License: MIT
Install:
bash docker run -d \
View Certimate on GitHub · More about Certimate
18. Actions Runner Controller by actions
Actions Runner Controller (ARC) is a Kubernetes operator that orchestrates and scales self-hosted runners for GitHub Actions.
With ARC, you can create runner scale sets that automatically scale based on the number of workflows running in your repository, organization, or enterprise. Because controlled runners can be ephemeral and based on containers, new runner instances can scale up or down rapidly and cleanly. For more information about autoscaling, see "Autoscaling with self-hosted runners."
You can set up ARC on Kubernetes using Helm, then create and run a workflow that uses runner scale sets. For more information about runner scale sets, see "Deploying runner scale sets with Actions Runner Controller."
Stars: 6.5k
Language: Go
License: Apache-2.0
View Actions Runner Controller on GitHub · More about Actions Runner Controller
19. Kueue by kubernetes-sigs
Kueue is a set of APIs and controller for job queueing. It is a job-level manager that decides when a job should be admitted to start (as in pods can be created) and when it should stop (as in active pods should be deleted).
Read the overview and watch the Kueue-related talks & presentations to learn more. Job management: Support job queueing based on priorities with different strategies: StrictFIFO and BestEffortFIFO. Advanced Resource management: Comprising: resource flavor fungibility, Fair Sharing, cohorts and preemption with a variety of policies between different tenants. Integrations: Built-in support for popular jobs, e.g. BatchJob, Kubeflow training jobs, RayJob, RayCluster, JobSet, plain Pod and Pod Groups. System insight: Built-in prometheus metrics to help monitor the state of the system, and on-demand visibility endpoint for monitoring of pending workloads. AdmissionChecks: A mechanism for internal or external components to influence whether a workload can be admitted. Advanced autoscaling support: Integration with cluster-autoscaler's provisioningRequest via admissionChecks. All-or-nothing with ready Pods: A timeout-based implementation of All-or-nothing scheduling. Partial admission and dynamic reclaim: mechanisms to run a job with reduced parallelism, based on available quota, and to release the quota the pods complete. Mixing training and inference: Simultaneous management of batch workloads along with serving workloads (such as Deployments or StatefulSets) Multi-cluster job dispatching: called MultiKueue, allows to search for capacity and off-load the main cluster. Topology-Aware Scheduling: Allows to optimize the Pod-to-Pod communication throughput by scheduling aware of the data-center topology. API version: v1beta2, respecting Kubernetes Deprecation Policy. Up-to-date documentation. Test coverage: Unit test testgrid. Integration tests: Baseline suite shard-0 shard-1 shard-2 MultiKueue suite testgrid. E2E tests: Baseline suites for Kubernetes 1.34 1.35 1.36 on Kind. Extended suites for Kubernetes on Kind: 1.34: shard-0 shard-1 shard-2 1.35: shard-0 shard-1 shard-2 1.36: shard-0 shard-1 shard-2 TAS: Baseline suite testgrid. Extended suite: shard-0 shard-1 Sequential tests: Baseline suites: shard-0 shard-1 Extended suites: shard-0 shard-1 E2E Cert Manager test testgrid. DRA test testgrid. MultiKueue: Baseline suite testgrid. Extended suites: shard-0 shard-1 MultiKueue DRA test testgrid. Scheduling performance tests: Baseline suite testgrid. TAS suite testgrid. Large-Scale suite testgrid. Scalability verification via performance tests. Monitoring via metrics. Security: RBAC based accessibility. Stable release cycle (2-3 months). Adopters running on production.
Based on community feedback, we continue to simplify and evolve the API to address new use cases.
Stars: 3k
Language: Go
License: Apache-2.0
Final thoughts on security & infrastructure GitHub repos
The best security & infrastructure repo is the one you come back to. Pick 2 or 3 from this list, give them a month, and keep the ones you look forward to.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More GitHub repos
More repo topics
More free tools
Related MCP servers & CLIs
The most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.


























































