Seedfire is a self-hosted access platform for your servers, firewalls, cameras and desktops — behind NAT, across sites, with zero public ports and zero-setup certificate SSH.
$ seedfire seedfire — 3 group(s), 2 asset(s) 1 bwi/ (22 assets) 2 mia/ (4 assets) 3 office/ (9 assets) 【SSH terminal】 4 web01-ssh on 127.0.0.1:22 5 db01-ssh on 127.0.0.1:22 (number = open · /word find · s/w/d/o type · q quit) >
One self-hosted control plane. Agents dial out — nothing listens on the internet.
Devices connect outbound over encrypted STCP tunnels. Your firewalls, UPSes, iDRACs and NVRs get reachable — without ever being exposed.
Short-lived SSH certificates are issued per connection. No key copying, no password sprawl, instant revocation when someone leaves.
Enroll a Linux, Windows or macOS machine with a single command. Uninstall is just as clean — one line, nothing left behind.
A tray app for clicking, a bastion-style CLI menu for typing. Update either half — the other follows automatically. They never drift apart.
Push signed, checksum-verified upgrades to the whole fleet in batches with automatic rollback gates. No SSH-ing into twenty boxes.
Agents probe every asset target each minute. Debounced down/up alerts reach your webhook or Telegram before your users notice.
Organise thousands of assets as site/type trees (bwi/cams, bwi/net). Grant whole groups to people or machines; browse them like directories.
Every login, grant, connection and upgrade is an audit row. Stored credentials are sealed with a master key and delivered per-connect, never displayed.
Single Go binary, SQLite state, native systemd. Your data never touches a third-party cloud — the control plane is a box you own.
Three steps from nothing to certificate SSH.
One binary on any Linux box. It's the frps auth plugin, the API, the web console and the CA — all in one.
manager-server servePaste the one-liner from the admin console on the machine you want to reach.
curl -fsSL https://your-server:8443/install.sh | sudo -E bashSign in once on your laptop, then reach anything you're granted — by name, number or menu.
$ seedfire connect web01
web01 $ _A VPN gets you a network. Seedfire gets you the machine — with identity, audit and control.
| Seedfire | Traditional VPN | |
|---|---|---|
| Public attack surface | none — agents dial out | VPN port exposed to the internet |
| Access granularity | per asset, per user, per group | whole subnets once you're in |
| SSH logins | short-lived certificates, auto-issued | keys and passwords to manage |
| Audit trail | every connection, grant and upgrade | connection logs at best |
| Fleet software upgrades | built in, batched, verified | not its job |
Seedfire is in active development and runs real multi-site fleets today.