Octelium
A self-hosted zero trust access platform that can act as a remote access VPN or ZTNA gateway.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Octelium
Octelium is an open-source platform you run on your own infrastructure to control access to internal services. It can work as a remote access VPN, a zero trust network access (ZTNA) platform, an API, AI and MCP gateway, an ngrok-style tunnel for exposing services, or the base of a homelab setup.
You install command-line tools and then deploy an Octelium cluster. It suits administrators and homelab users who want identity-based access to private resources without a hosted commercial service.
Strengths
- Combines VPN, ZTNA and gateway roles in one self-hosted system
- Open source under AGPL-3.0 and Apache-2.0 licences
- Can replace ngrok-style tunnels for exposing services
Limitations
- Requires deploying and operating a cluster
- Broad scope means more to learn than a simple VPN
Details
- Pricing
- FreeFree and open source.
- License
- AGPL-3.0, Apache-2.0
- Developer
- The Octelium contributors
- Platforms
- Self-hosted, Command line
- How it runs
- Downloadable app, Self-hosted
- Best suited for
- Administrators and homelab users wanting self-hosted zero trust access
- Categories
- VPN, IT administration
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to Octelium
Compare allSoftware that can replace Octelium for an important use case, and what changes if you switch.
OpenZiti
An open-source zero trust networking platform that connects services by identity instead of IP address.
OpenZiti is an open-source self-hostable zero trust platform using identity-based access with no open inbound ports, plus SDKs to embed connectivity in applications.
NetBird
A WireGuard-based mesh network with single sign-on, multi-factor authentication and access policies, self-hostable or managed.
NetBird provides WireGuard mesh networking with SSO, MFA and group access policies, self-hostable under the AGPL or used as a managed service.
Firezone
WireGuard-based zero trust access with self-hosted gateways.
Firezone offers WireGuard-based zero trust access with self-hosted gateways and identity provider policies, but its control plane is hosted by the vendor.
defguard
A self-hosted WireGuard VPN platform with built-in identity management and multi-factor authentication per connection.
defguard is a self-hosted WireGuard platform enforcing MFA on each connection with LDAP, Active Directory and OIDC, though some features are in paid enterprise plans.
Twingate
An identity-based network access service meant to replace a traditional VPN for teams.
Twingate is a hosted identity-based access service for teams, removing the need to run a cluster but not self-hostable and closed source.
Pritunl
A self-hosted VPN server for OpenVPN, WireGuard and IPsec, managed through a web interface.
Pritunl is a self-hosted OpenVPN, WireGuard and IPsec server with a web interface, offering traditional remote-access VPN rather than ZTNA gateway features.
Similar software
Related functionality, not necessarily a direct replacement.
Tailscale
Builds a private network between your own devices using WireGuard, without opening ports or running a server.
headscale
A self-hosted, open-source implementation of the Tailscale control server, so your mesh VPN does not depend on a company.
Netmaker
Self-hosted platform for building and managing WireGuard mesh networks.
ocserv
An open-source Linux SSL VPN server compatible with OpenConnect and AnyConnect clients.
OpenVPN Access Server
A self-hosted business VPN server with a web admin interface, free for two simultaneous connections.
WireGuard
A small, fast VPN protocol and set of official clients that connect two machines by exchanging public keys.