ランキングに戻る

veops/oneterm

Gov1ops.com

Provide secure access and control over all infrastructure

golangsshterminalvueonetermrdpvncbastion
スター成長
スター
1.5k
フォーク
152
週間成長
Issue
18
5001k
2024年2月2024年11月2025年9月2026年7月
成果物Go Modulesgo get github.com/veops/oneterm
README

oneterm_banner

Apache License 2.0 the latest release version go>=1.18 UI Stars Badge Forks Badge

A Simple, Lightweight, Flexible Bastion Host.

veops%2Foneterm | Trendshift

English · 中文(简体)

What is OneTerm

OneTerm is a simple, lightweight, and flexible enterprise-level bastion host product. Based on the 4A concept: Authentication, Authorization, Account, and Audit, it ensures system security and compliance through strict access control and monitoring functions.

Core Features

  • Access Control: OneTerm acts as an intermediary site, restricting direct access to critical systems. Users must first authenticate through OneTerm before accessing other servers or systems.

  • Security Audit: OneTerm can record user logins and activities, providing audit logs for investigation when security incidents occur. This helps ensure that every user's behavior is traceable and auditable.

  • Jump Server Access: OneTerm provides a jump server approach where users can connect to other internal servers through OneTerm. This approach helps reduce the risk of directly exposing internal servers, as only OneTerm needs to be externally accessible.

  • Password Management: OneTerm can implement enhanced password policies and centrally manage passwords through a single entry point. This helps improve the password security of the entire system.

  • Session Recording: OneTerm can record user sessions with servers, which is very useful for monitoring and investigating privileged user activities. If security incidents occur, session recordings can be replayed to understand detailed operations.

  • Prevent Direct Attacks: Since OneTerm is the only entry point to systems and resources, it can become the main barrier for attackers. This helps reduce the risk of direct attacks on internal systems.

  • Unified Access: OneTerm provides a single entry point through which users can access different systems without having to remember multiple login credentials. This improves user convenience and work efficiency.

Product Advantages

  • Authentication and Authorization: OneTerm features powerful and flexible authentication and authorization mechanisms. This includes support for multi-factor authentication, ensuring that only authorized users can access internal network resources, and providing fine-grained user permission management.

  • Secure Communication: OneTerm supports secure communication protocols and encryption technologies to protect data transmission between users and internal servers. This helps prevent man-in-the-middle attacks and data leaks.

  • Audit and Monitoring: OneTerm has powerful audit and monitoring capabilities, recording user activities and generating audit logs. This helps track security events, identify potential threats, and meet compliance requirements.

  • Remote Management and Session Isolation: OneTerm supports remote management, enabling administrators to securely manage internal servers. At the same time, it features session isolation to ensure that access between users is mutually isolated, preventing lateral escalation attacks.

  • Tight Integration with Open Source CMDB: OneTerm is tightly integrated with Veops CMDB (open source), allowing users to import assets from CMDB with one click, ensuring convenient operation and smooth processes.

Technology Stack

  • Backend: Go
  • Frontend: Vue.js
  • UI Component Library: Ant Design Vue

Follow Us

Welcome to Star and follow us to get the latest updates!

star us

Project Overview

dashboard terminal
work_station access_auth
system_settings access_time

Quick Start

Method 1: Quick Deploy (Default Password)

  • Docker Compose Installation
    git clone https://github.com/veops/oneterm.git
    cd oneterm/deploy
    docker compose up -d
    

Method 2: Secure Deploy (Custom Passwords)

  • For production environments, use the setup script to configure secure passwords:

    git clone https://github.com/veops/oneterm.git
    cd oneterm/deploy
    ./setup.sh
    docker compose up -d
    

    The setup script will:

    • Generate secure random passwords or let you set custom ones
    • Update all configuration files with your passwords
    • Create backup files for safety
  • Access

    • Open your browser and visit: http://127.0.0.1:8666
    • Username: admin
    • Password: 123456 (default) or your custom password if using setup.sh

Development

For developers who want to contribute to OneTerm or set up a local development environment:

🚀 Quick Development Setup

# Clone repository
git clone https://github.com/veops/oneterm.git
cd oneterm/deploy

# Frontend development (live editing)
./dev-start.sh frontend

# Backend development (live editing)  
./dev-start.sh backend

📖 Detailed Development Guide

For complete setup instructions, troubleshooting, and development workflows:

Requirements: Docker, Node.js 14.17.6+, Go 1.21.3+

Contributing

We welcome all developers to contribute code and improve and extend this project. Please read our Contribution Guide first. Additionally, you can support Veops open source through social media, events, and sharing.

More Open Source

  • CMDB: Simple, lightweight, and versatile operational CMDB
  • ACL: A general permission control management system.
  • messenger: A simple and lightweight message sending service.

Contact Us

関連リポジトリ
practical-tutorials/project-based-learning

Curated list of project-based tutorials

PythonPyPIMIT Licensetutorialproject
274.6k35.4k
avelino/awesome-go

A curated list of awesome Go frameworks, libraries and software

GoGo ModulesMIT Licensegolanggolang-library
awesome-go.com
178.8k13.4k
ollama/ollama

Get up and running with Kimi-K2.6, GLM-5.2, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.

GoGo ModulesMIT Licensellamallm
ollama.com
176.6k17.1k
golang/go

The Go programming language

GoGo ModulesBSD 3-Clause "New" or "Revised" Licenseprogramming-languagelanguage
go.dev
135.3k19.3k
caddyserver/caddy

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

GoGo ModulesApache License 2.0goweb-server
caddyserver.com
74.2k4.8k
unionlabs/union

The trust-minimized, zero-knowledge bridging protocol, designed for censorship resistance, extremely high security, and usage in decentralized finance.

Rustcrates.ioApache License 2.0blockchaincosmos
union.build
73.9k3.9k
moby/moby

The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems

GoGo ModulesApache License 2.0dockercontainers
mobyproject.org
71.9k19k
nektos/act

Run your GitHub Actions locally 🚀

GoGo ModulesMIT Licensegithub-actionsgolang
nektosact.com
71.2k2k
traefik/traefik

The Cloud Native Application Proxy

GoGo ModulesMIT Licensemicroservicedocker
traefik.io
64.1k6.1k
santifer/career-ops

Open-source AI job search: scan job portals, evaluate listings with a structured A-F rubric into a 1.0-5.0 score, tailor your CV, track applications — runs locally in your AI coding CLI (Claude Code, Codex, OpenCode, Antigravity…)

JavaScriptnpmMIT Licenseai-agentanthropic
career-ops.org
60.9k12k
pocketbase/pocketbase

Open Source realtime backend in 1 file

GoGo ModulesMIT Licenseauthenticationbackend
pocketbase.io
60.1k3.6k
rclone/rclone

"rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive, Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex Files

GoGo ModulesMIT Licensegolanggo
rclone.org
58.6k5.2k