Seedfire logo

Reach every machine.
Expose none.

Seedfire is a self-hosted access platform for your servers, firewalls, cameras and desktops — behind NAT, across sites, with zero public ports and zero-setup certificate SSH.

operator@laptop — seedfire
$ seedfire
seedfire — 3 group(s), 2 asset(s)
    1  bwi/       (22 assets)
    2  mia/       (4 assets)
    3  office/    (9 assets)
【SSH terminal】
    4  web01-ssh      on   127.0.0.1:22
    5  db01-ssh       on   127.0.0.1:22
(number = open · /word find · s/w/d/o type · q quit) >

Built for real infrastructure

One self-hosted control plane. Agents dial out — nothing listens on the internet.

🔒

Zero public ports

Devices connect outbound over encrypted STCP tunnels. Your firewalls, UPSes, iDRACs and NVRs get reachable — without ever being exposed.

🎫

Certificate SSH, zero setup

Short-lived SSH certificates are issued per connection. No key copying, no password sprawl, instant revocation when someone leaves.

One-line install

Enroll a Linux, Windows or macOS machine with a single command. Uninstall is just as clean — one line, nothing left behind.

🖥️

Desktop app + CLI, one product

A tray app for clicking, a bastion-style CLI menu for typing. Update either half — the other follows automatically. They never drift apart.

🚀

Fleet upgrades from one seat

Push signed, checksum-verified upgrades to the whole fleet in batches with automatic rollback gates. No SSH-ing into twenty boxes.

📟

Knows when things break

Agents probe every asset target each minute. Debounced down/up alerts reach your webhook or Telegram before your users notice.

🗂️

Groups & subgroups

Organise thousands of assets as site/type trees (bwi/cams, bwi/net). Grant whole groups to people or machines; browse them like directories.

🧾

Everything audited

Every login, grant, connection and upgrade is an audit row. Stored credentials are sealed with a master key and delivered per-connect, never displayed.

🏠

Yours, entirely

Single Go binary, SQLite state, native systemd. Your data never touches a third-party cloud — the control plane is a box you own.

Up and running in minutes

Three steps from nothing to certificate SSH.

Deploy the server

One binary on any Linux box. It's the frps auth plugin, the API, the web console and the CA — all in one.

manager-server serve

Enroll devices

Paste the one-liner from the admin console on the machine you want to reach.

curl -fsSL https://your-server:8443/install.sh | sudo -E bash

Connect

Sign in once on your laptop, then reach anything you're granted — by name, number or menu.

$ seedfire connect web01 web01 $ _

Why not just a VPN?

A VPN gets you a network. Seedfire gets you the machine — with identity, audit and control.

SeedfireTraditional VPN
Public attack surfacenone — agents dial outVPN port exposed to the internet
Access granularityper asset, per user, per groupwhole subnets once you're in
SSH loginsshort-lived certificates, auto-issuedkeys and passwords to manage
Audit trailevery connection, grant and upgradeconnection logs at best
Fleet software upgradesbuilt in, batched, verifiednot its job

Ready to own your access?

Seedfire is in active development and runs real multi-site fleets today.