Features
What Kalitka does today
Only capabilities that exist right now. Anything experimental is labelled as such.
Web Gate
- Reverse-proxy access approval for Traefik, nginx, Caddy and Envoy
- Temporary access with expiring grants
- Google authentication
- Resource-scoped access policies
Human Approval
- Telegram approvals from an existing chat workflow
- Email approval channel using short-lived one-time capabilities
- Web control plane for pending requests, approve / deny and history
experimental
SSH
- PAM-based approval inside the SSH login flow
- One-time grants for a single session
- Session lifecycle tied to the approved grant
Audit & State
- Durable access requests and sessions
- Replay protection through resolve-once semantics
- Audit history you can read after the fact
Deployment
- Self-hosted, in your own infrastructure
- Docker / container deployment
- SQLite-based local deployment
What Kalitka is not
- Not an identity provider
- Not a VPN replacement or a WAF
- Not another password database
