openziti/ziti

The parent project for OpenZiti. Here you will find the executables for a fully zero-trust, programmable network @OpenZiti

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 58 minutes ago
Added to GitGenius on September 15th, 2026
Created on November 22nd, 2019
Open Issues & Pull Requests: 326 (+0)
GitHub issues: Enabled
Number of forks: 273
Total Stargazers: 4,395 (+0)
Total Subscribers: 39 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 0.0 hours
Mean response time: 54.9 days
90th percentile: 148.0 days
Tracked items: 743

Most active contributors

Sign in to see contributor activity.

How this project is maintained

About 16% of issues opened in the past year have never received a reply. Only 28% of open issues come from outside the core team — the tracker reads mainly as internal planning. 28% of tracked open issues have had no activity in three months. 72% of issues opened in the past year have been closed, leaving a working backlog. Three people close 88% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 185
New in 7 days: 18
Closed in 7 days: 5
Avg open age: 321 days
Stale 30+ days: 132
Stale 90+ days: 100

Recent activity

Opened in 7 days: 18
Closed in 7 days: 5
Comments in 7 days: 2
Events in 7 days: 51

Top labels

  • bug (140)
  • controller (97)
  • router (86)
  • enhancement (75)
  • distributed-control (69)
  • backport (64)
  • security (41)
  • CLI (38)

Detailed Description

OpenZiti is an open-source zero-trust networking platform that makes network services invisible to unauthorized users and provides encrypted end-to-end connectivity for every connection.

The platform addresses the problem of securing network access without relying on network perimeter defenses or VPN concentrators. It works by requiring cryptographic identity authentication for every connection, applying policy-based authorization, and encrypting traffic end-to-end. The approach supports both existing applications through lightweight tunnelers that require no code changes and new applications through embedded SDKs. Services become invisible to the internet with zero listening ports, eliminating attack surface while allowing only authorized clients to connect through the overlay network.

OpenZiti suits organizations replacing VPNs, securing APIs and services from public exposure, managing non-human workload identity across clouds, and implementing zero-trust architecture for workload-to-workload communication. It works across multiple deployment models and environments including Kubernetes, multi-cloud setups, hybrid infrastructure, and self-hosted services. The platform is practical for both brownfield environments with existing applications and greenfield development where SDKs can be embedded from the start.

The project maintains active development with regular updates to its core networking components and controller functionality. The codebase shows ongoing refinement of the zero-trust architecture and policy engine. Community engagement appears consistent through documented use cases spanning VPN replacement, dark APIs, IoT device identity, workload security, AI agent communication, and cross-cluster Kubernetes connectivity. The project provides multiple SDKs and tunneler implementations, indicating sustained investment in supporting diverse deployment scenarios.