No inbound firewall rule, on any network you manage

A lightweight worker dials out to Akku. Outbound HTTPS on 443, and nothing else.

Most privileged access management asks for one of two things in an isolated network: a full deployment inside every zone, or a firewall rule a security team will not sign. AkkuReka asks for neither. A lightweight worker sits inside the network segment with your targets and dials out to Akku over TLS 1.3. Nothing connects inward.

What the worker needs

Linux on Ubuntu 20.04 or later, RHEL 8 or later, or Debian 11 or later, or a container on Docker or Kubernetes. Two vCPUs and 2GB of memory, four of each for heavy session loads. Outbound HTTPS on port 443 to Akku, and network reach to the targets on their existing ports. It installs as a single binary or a container image with no dependency chain.

Adding a network

One worker covers a segment. Adding another isolated network means another worker rather than another deployment of the platform, and multiple workers can run in parallel in the same segment for redundancy and load. Your firewall does not change.

When the platform itself has to be inside

Where data sovereignty requires it, or where the environment has no route out at all, the whole Akku platform deploys on-premises inside your own infrastructure rather than as a cloud service with a worker reaching into it.

What the target sees

Targets are never directly reachable from the internet. Only the worker talks to them, and it needs no agent installed on any of them.

More in PAM

See how it works.

Every privileged session runs through the proxy, with a credential the user never sees and a recording of what happened. The worker dials out, so nothing needs an inbound firewall rule.

No standing accessAppend-only audit logOutbound only, no inbound ports