SeyalRun
Secure. Controlled.
Automated.

A standalone PAM and job-automation platform for your server fleet — vaulted credentials, a browser terminal, recorded sessions, and automation, with no monitoring stack required. Already run Zabbix? It integrates there too, natively.

Everything a PAM console needs, nothing it doesn't

Twelve capabilities, each doing one job — so an incident in one never means trusting all of them.

12 Capabilities
🖥️

Session Recording & Command Audit

🔗

Connect Hosts from UI

🛡️

Role-Based Access Control

🗂️

Host & User Groups

🔒

Security First

📜

Automation Playbooks

🚫

Command Blocking (Groups & Nodes)

📚

Centralized Log Backend

🔐

Credential Vault

🧩

Zabbix Integration

📡

Monitoring API

🔌

API for Integration

terminal · recordingAUDITED

Session recording & command audit

Every SSH session recorded end-to-end and replayable — not just that someone logged in, but every command they ran.

inventory-serviceUI

Connect hosts from the UI

Add, test, and manage SSH hosts directly from the browser — no config files or API calls needed to onboard a server.

identity-serviceRBAC

Role-based access control

Fine-grained roles decide who can view, connect to, or run jobs on which hosts — enforced on every request.

identity · inventoryGROUPS

Host groups, user groups & roles

Organize servers into host groups and people into user groups, then grant access by group, not one at a time.

platform-wideBY DESIGN

Security first

Encrypted vault, fail-fast config with no default secrets, redacted logs, clickjacking protection — the architecture, not an add-on.

automation-serviceJOBS

Automation playbooks

Run Ansible-style playbooks or raw scripts across your fleet from reusable job templates, scoped to allowed hosts.

terminal-serviceBLOCKED

Command blocking for groups & nodes

Block specific commands, scoped to exactly the host, host group, user, or user group you choose — stop a risky command before it runs.

automation-serviceES / S3

Centralized log backend

Ship audit and session logs to Elasticsearch or S3 from one Admin screen — no per-service log wrangling.

inventory-serviceAES-256-GCM

Credential vault

SSH credentials encrypted at rest, scrypt-derived keys, never logged or exposed in plaintext.

zabbix-integrationOPTIONAL

Zabbix integration

Already run Zabbix? A frontend module adds a SeyalRun menu and one-click terminal icons — one login, not two.

edge-proxy1 REQ/MIN

Monitoring API

One aggregate HTTP endpoint reports health and metrics for every service — no sidecar, no Docker socket exposed.

api-gatewayPAT

API for integration

Every feature is reachable over its REST API — issue scoped Personal Access Tokens to plug into your own tooling.

Read the docs

Configuration reference, architecture, security model, and the Zabbix module install walkthrough.