Octelium is an open source, self-hosted unified secure-access platform built for modern infrastructure and hybrid environments. It positions itself as more than a typical VPN; it supports zero-trust network access (ZTNA), “BeyondCorp”-style access, API/AI gateway functionality, and even serves as a PaaS-like deployment surface. One of its key strengths is identity-based, application-layer (L7) aware control, meaning access decisions are made per request, with context and policy rather than simple network-level allow/block rules. It supports both client-based (e.g., WireGuard/QUIC tunnels) and client-less access models, which makes it flexible for both human users and automated workloads. The project also highlights self-hosted, no hidden “server-side” locked components, giving organizations greater ownership and control over access, rather than relying on proprietary SaaS.
Features
- Identity- and context-aware, per-request access control rather than static VPN rules
- Built-in support for WireGuard/QUIC client-tunnels and client-less browser/HTTP access
- API/AI gateway capability for microservices and large-model workloads
- Declarative GitOps/CLI/Helm support for configuration and scaling
- Open source and self-hosted, no hidden server-side SaaS lock-in
- Built-in visibility and auditing via OpenTelemetry for access and service metrics