Self-hosted, open source

Give your team SSH access without giving away the keys.

Brun puts a browser between your engineers and your infrastructure. Every command gets recorded, every password gets redacted automatically, and every session can be watched live — without installing anything on anyone's laptop.

Runs on your own infrastructure. No account, no phone-home, no vendor.

admin@core-switch-01 — ssh
recording keystrokes logged

Someone shares a root password in Slack "just this once." A contractor's VPN access never gets revoked. Nobody can say who ran that command on the production database last Tuesday. Commercial PAM tools fix this — for a price tag and a procurement cycle most teams can't justify for a handful of servers.

Brun is the version of that tool you can actually run today.

What actually happens when someone connects

Not a feature list — the actual behavior, every time a session opens.

Video, not just logs

Watch exactly what happened, not just what was typed.

Every SSH, RDP, and VNC session is recorded automatically from the moment it opens. Recordings play back frame-by-frame right in the browser — no separate video player, no format conversion, no plugin.

Recordings are stored per user, so auditing "everything Alice did this month" is as easy as reviewing one incident.

core-switch-jkt-01_20260904
02:1405:47
Readable transcripts

A command-by-command transcript — with passwords automatically blacked out.

Every keystroke is grouped into full command lines, the way you'd actually read a terminal transcript. Run sudo, su, or passwd, and Brun automatically redacts whatever gets typed next.

Redaction is a heuristic, not a guarantee — tuned to over-redact rather than risk a leak.

09:58:02whoami
09:58:17sudo systemctl restart nginx
09:58:19[REDACTED — likely password]
09:58:24systemctl status nginx
Watch, don't wait

See what's happening right now, not just what already happened.

Admins can join any active session in true read-only mode — no keyboard, no mouse, just visibility. Useful for supervising a contractor's first login, or checking in on a change mid-flight.

sdwan-edge-bandung-01 — bob4m 12sWatch
vm-windows-jumpbox-01 — carol0m 41sWatch

Any protocol you already use

SSH and Telnet for the CLI, RDP and VNC for desktops — including web consoles opened through an isolated browser.

Access scoped per user

Admins see and manage everything. Everyone else only sees the systems they've been explicitly given.

Audit log for your SIEM

Structured JSON Lines for every login, session, and admin action. Point Filebeat at it and you're done.

No agent, no install

Engineers connect from a browser tab. Nothing to install on a laptop, nothing to whitelist through a firewall.

We didn't rebuild the hard part

The part that has to be rock solid — actually proxying SSH, RDP, and VNC — is handled by guacd, the protocol engine behind Apache Guacamole. It's been in production use for over a decade.

Browser
no install
──▶
Brun
auth, RBAC, audit
──▶
guacd
protocol engine
──▶
your device
router · VM · server

Brun builds a purpose-made interface, access control layer, and audit trail on top of guacd — instead of reinventing a proxy from scratch.

Self-hosted means you're actually in control.

No cloud dependency, no per-seat license, nothing phones home. The source is open — read it, audit it, fork it, change it. If your security team needs to sign off on a tool before it touches production credentials, being able to read every line is the whole point.

View the repository

Stop passing root passwords around.

Brun is a Docker Compose file away from running in your environment.