Features

What Kalitka does today

Only capabilities that exist right now. Anything experimental is labelled as such.

Web Gate

  • Reverse-proxy access approval for Traefik, nginx, Caddy and Envoy
  • Temporary access with expiring grants
  • Google authentication
  • Resource-scoped access policies

Human Approval

  • Telegram approvals from an existing chat workflow
  • Email approval channel using short-lived one-time capabilities
  • Web control plane for pending requests, approve / deny and history
experimental

SSH

  • PAM-based approval inside the SSH login flow
  • One-time grants for a single session
  • Session lifecycle tied to the approved grant

Audit & State

  • Durable access requests and sessions
  • Replay protection through resolve-once semantics
  • Audit history you can read after the fact

Deployment

  • Self-hosted, in your own infrastructure
  • Docker / container deployment
  • SQLite-based local deployment

What Kalitka is not

  • Not an identity provider
  • Not a VPN replacement or a WAF
  • Not another password database