<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tanpa vpn - Hamradio.my</title>
	<atom:link href="https://hamradio.my/tag/tanpa-vpn/feed/" rel="self" type="application/rss+xml" />
	<link>https://hamradio.my/tag/tanpa-vpn/</link>
	<description>Amateur Radio, Tech Insights and Product Reviews</description>
	<lastBuildDate>Wed, 11 Jun 2025 13:11:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://hamradio.my/wp-content/uploads/2026/02/cropped-cropped-image-removebg-preview-3-32x32.png</url>
	<title>tanpa vpn - Hamradio.my</title>
	<link>https://hamradio.my/tag/tanpa-vpn/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Build Your Own Zero Trust Access Gateway with Octelium (Open Source &#038; Self-Hosted)</title>
		<link>https://hamradio.my/2025/08/build-your-own-zero-trust-access-gateway-with-octelium-open-source-self-hosted/</link>
					<comments>https://hamradio.my/2025/08/build-your-own-zero-trust-access-gateway-with-octelium-open-source-self-hosted/#comments</comments>
		
		<dc:creator><![CDATA[9M2PJU]]></dc:creator>
		<pubDate>Sat, 02 Aug 2025 13:05:04 +0000</pubDate>
				<category><![CDATA[do it yourself]]></category>
		<category><![CDATA[free open source software]]></category>
		<category><![CDATA[self hosted]]></category>
		<category><![CDATA[zero trust]]></category>
		<category><![CDATA[akses selamat]]></category>
		<category><![CDATA[api gateway]]></category>
		<category><![CDATA[capaian jauh]]></category>
		<category><![CDATA[container security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[devops]]></category>
		<category><![CDATA[devops malaysia]]></category>
		<category><![CDATA[identity aware proxy]]></category>
		<category><![CDATA[infrastruktur selamat]]></category>
		<category><![CDATA[kawalan akses]]></category>
		<category><![CDATA[kendiri hos]]></category>
		<category><![CDATA[keselamatan kontena]]></category>
		<category><![CDATA[keselamatan rangkaian]]></category>
		<category><![CDATA[keselamatan siber]]></category>
		<category><![CDATA[kubernetes]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[pintu masuk api]]></category>
		<category><![CDATA[proksi sedar identiti]]></category>
		<category><![CDATA[remote access]]></category>
		<category><![CDATA[secure infrastructure]]></category>
		<category><![CDATA[secure tunnels]]></category>
		<category><![CDATA[ssh access]]></category>
		<category><![CDATA[sumber terbuka]]></category>
		<category><![CDATA[tanpa konfigurasi]]></category>
		<category><![CDATA[tanpa vpn]]></category>
		<category><![CDATA[vpn alternative]]></category>
		<category><![CDATA[zero config vpn]]></category>
		<guid isPermaLink="false">https://hamradio.my/?p=7825</guid>

					<description><![CDATA[<p>What is Octelium? Octelium is a free and open source, self-hosted platform that provides zero trust secure access to resources across any environment. It’s designed as a modern, unified alternative to traditional VPNs, ZTNA platforms, API gateways, PaaS hosting, Kubernetes ingress, reverse proxies, and even tools like ngrok. Whether you&#8217;re managing a corporate infrastructure, hosting [&#8230;]</p>
<p>The post <a href="https://hamradio.my/2025/08/build-your-own-zero-trust-access-gateway-with-octelium-open-source-self-hosted/">Build Your Own Zero Trust Access Gateway with Octelium (Open Source &amp; Self-Hosted)</a> appeared on <a href="https://hamradio.my">Hamradio.my - Amateur Radio, Tech Insights and Product Reviews</a> by <a href="https://hamradio.my/author/9m2pju/">9M2PJU</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1 class="wp-block-heading">What is Octelium?</h1>



<p class="wp-block-paragraph"><strong>Octelium</strong> is a free and open source, self-hosted platform that provides <strong>zero trust secure access</strong> to resources across any environment. It’s designed as a modern, unified alternative to traditional VPNs, ZTNA platforms, API gateways, PaaS hosting, Kubernetes ingress, reverse proxies, and even tools like ngrok.</p>



<p class="wp-block-paragraph">Whether you&#8217;re managing a corporate infrastructure, hosting containerized apps, securing SaaS API access, or just running a homelab, Octelium offers a scalable, <strong>identity-based</strong>, <strong>application-layer (L7)</strong> access solution with both <strong>client-based (WireGuard/QUIC)</strong> and <strong>client-less (BeyondCorp-style)</strong> capabilities.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Key Use Cases</h2>



<p class="wp-block-paragraph">Octelium is extremely flexible and can be used in the following scenarios:</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f510.png" alt="🔐" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Unified Zero Trust Access (ZTNA/BeyondCorp)</h3>



<p class="wp-block-paragraph">Replace commercial ZTNA solutions (like Cloudflare Access, Teleport, or Zscaler) with a self-hosted alternative supporting both client-based and client-less access.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f310.png" alt="🌐" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Modern Remote Access VPN</h3>



<p class="wp-block-paragraph">Octelium works like a zero-config, L7-aware VPN using WireGuard/QUIC tunnels—no complex routing or network configs needed.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f504.png" alt="🔄" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Secure Tunnels &amp; Reverse Proxy</h3>



<p class="wp-block-paragraph">Set up programmable, secure tunnels to expose private services behind NAT—similar to ngrok or Cloudflare Tunnel.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f680.png" alt="🚀" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Self-Hosted PaaS</h3>



<p class="wp-block-paragraph">Deploy and scale containerized apps with secure access controls—an open source alternative to platforms like Vercel or Netlify.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f501.png" alt="🔁" class="wp-smiley" style="height: 1em; max-height: 1em;" /> API Gateway</h3>



<p class="wp-block-paragraph">Manage and secure your microservices, with L7-aware routing, context-aware policies, and built-in authentication support.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f916.png" alt="🤖" class="wp-smiley" style="height: 1em; max-height: 1em;" /> AI Gateway</h3>



<p class="wp-block-paragraph">Add access control and observability to LLM providers or self-hosted AI APIs, including usage tracking and per-request access.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f511.png" alt="🔑" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Secret-less SaaS Access</h3>



<p class="wp-block-paragraph">Grant secure, token-free access to SaaS APIs and databases for teams or workloads—no more sharing API keys or tokens.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f504.png" alt="🔄" class="wp-smiley" style="height: 1em; max-height: 1em;" /> MCP/A2A Architectures</h3>



<p class="wp-block-paragraph">Secure identity-aware infrastructure for Agent-to-Agent or Model Context Protocol (MCP)-based systems.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2638.png" alt="☸" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Kubernetes Ingress Alternative</h3>



<p class="wp-block-paragraph">Route to any internal resource—not just Kubernetes services—based on identity, headers, request content, or time of day.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3e0.png" alt="🏠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Homelab Gateway</h3>



<p class="wp-block-paragraph">Connect and access all your homelab resources securely—cloud VMs, Raspberry Pis, routers, apps, and more.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Main Features</h2>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Unified Zero Trust Architecture</h3>



<p class="wp-block-paragraph">Octelium uses identity-aware proxies instead of IP-based segmentation. This enables:</p>



<ul class="wp-block-list">
<li>Secure access to any private/public resource.</li>



<li>Support for both client-based (VPN-like) and client-less (browser-based) access.</li>



<li>Integration with any identity provider (OIDC, SAML, GitHub OAuth, etc.).</li>



<li>Fine-grained, per-request access control via policy-as-code.</li>
</ul>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f510.png" alt="🔐" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Secret-less, Dynamic Access</h3>



<p class="wp-block-paragraph">Octelium supports dynamic access to:</p>



<ul class="wp-block-list">
<li>HTTP/gRPC APIs</li>



<li>SSH (no keys needed)</li>



<li>Kubernetes clusters</li>



<li>Databases (PostgreSQL, MySQL)</li>



<li>Any mTLS-based resource</li>
</ul>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dc.png" alt="📜" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Policy-as-Code with CEL &amp; OPA</h3>



<p class="wp-block-paragraph">Write composable, dynamic access policies using <strong>Common Expression Language (CEL)</strong> and <strong>Open Policy Agent (OPA)</strong>.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f512.png" alt="🔒" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Continuous Authentication</h3>



<p class="wp-block-paragraph">Supports strong MFA (e.g. WebAuthn/Yubikey) and secret-less OIDC-based workload identity.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50e.png" alt="🔎" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Full Visibility &amp; Audit Logging</h3>



<p class="wp-block-paragraph">Octelium exports per-request logs to <strong>OpenTelemetry OTLP</strong> collectors for centralized monitoring, logging, and security analysis.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f5a5.png" alt="🖥" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Embedded SSH Mode</h3>



<p class="wp-block-paragraph">SSH into any device or container—even without an SSH server—using Octelium’s embedded SSH capabilities.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9f1.png" alt="🧱" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Managed Containers</h3>



<p class="wp-block-paragraph">Securely deploy, manage, and expose containerized applications with public or private access modes.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2699.png" alt="⚙" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Declarative &amp; GitOps-Friendly</h3>



<p class="wp-block-paragraph">Use <code>octeliumctl</code> CLI to declaratively manage your cluster—like Kubernetes. All configurations can be stored in Git and applied programmatically.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Easy Setup</h2>



<h3 class="wp-block-heading">Install CLI Tools</h3>



<p class="wp-block-paragraph"><strong>Linux / macOS</strong></p>



<pre class="wp-block-code"><code>curl -fsSL https://octelium.com/install.sh | sh
</code></pre>



<p class="wp-block-paragraph"><strong>Windows (PowerShell)</strong></p>



<pre class="wp-block-code"><code>iwr https://octelium.com/install.ps1 -useb | iex
</code></pre>



<h3 class="wp-block-heading">Install a Single-Node Cluster</h3>



<p class="wp-block-paragraph">For personal or dev environments, you can install Octelium on a small VPS or local VM:</p>



<pre class="wp-block-code"><code>curl -o install-demo-cluster.sh https://octelium.com/install-demo-cluster.sh
chmod +x install-demo-cluster.sh
./install-demo-cluster.sh --domain yourdomain.com
</code></pre>



<p class="wp-block-paragraph">More installation guides and setup details are available in the <a href="https://octelium.com/docs">official docs</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Licensing</h2>



<ul class="wp-block-list">
<li><strong>Client-side</strong>: Apache 2.0</li>



<li><strong>Server-side (Cluster components)</strong>: AGPLv3<br>A commercial license is available for businesses needing AGPL alternatives.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Project Status &amp; Contributors</h2>



<p class="wp-block-paragraph">Octelium entered <strong>public beta in May 2025</strong>, and is stable with thousands of commits since 2020. It’s built and maintained by <strong>George Badawi</strong> via <strong>Octelium Labs LLC</strong>.</p>



<p class="wp-block-paragraph">External contributions are currently limited to issue reporting and feature requests, but this may change in the future.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Learn More</h2>



<ul class="wp-block-list">
<li><a href="https://octelium.com/docs"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d6.png" alt="📖" class="wp-smiley" style="height: 1em; max-height: 1em;" /> What is Octelium?</a></li>



<li><a href="https://octelium.com/zero-trust"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f510.png" alt="🔐" class="wp-smiley" style="height: 1em; max-height: 1em;" /> What is Zero Trust?</a></li>



<li><a href="https://octelium.com/how-it-works"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> How Octelium Works</a></li>



<li><a href="https://octelium.com/manage"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2699.png" alt="⚙" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Managing the Cluster</a></li>



<li><a href="https://octelium.com/policies"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dc.png" alt="📜" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Policies and Access Control</a></li>



<li><a href="https://octelium.com/contact"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e9.png" alt="📩" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Contact Support</a></li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Octelium</strong> is a fully self-hosted, transparent, and extensible zero trust access platform for the modern age—built to eliminate complexity, improve security, and give you total control over your infrastructure.</p>
<p>The post <a href="https://hamradio.my/2025/08/build-your-own-zero-trust-access-gateway-with-octelium-open-source-self-hosted/">Build Your Own Zero Trust Access Gateway with Octelium (Open Source &amp; Self-Hosted)</a> appeared on <a href="https://hamradio.my">Hamradio.my - Amateur Radio, Tech Insights and Product Reviews</a> by <a href="https://hamradio.my/author/9m2pju/">9M2PJU</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://hamradio.my/2025/08/build-your-own-zero-trust-access-gateway-with-octelium-open-source-self-hosted/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
	</channel>
</rss>
