The archive · Developer & Business Tools · Strategic decision · 2021–2022
Infra (YC W21) bet Kubernetes access control on open source, not enterprise sales
Ex-Docker founders built open-source Kubernetes access control for teams too small for enterprise sales; short-lived credentials are verified at destination.
Infra
What the business is
Infra (YC W21) makes open-source authentication and access management for Kubernetes, servers and databases: access granted and revoked by API or CLI, short-lived credentials, SSO via Okta, self-hosted via Docker or Kubernetes or run as a managed service.
How it started
Jeff and Michael had sold their first startup Kitematic to Docker and built Docker Desktop, then made Infra App, a Kubernetes client. From users and their own time at Docker they concluded that managing infrastructure access was becoming increasingly painful: large teams denied developers access, small teams granted admin to everyone, and teams in between hand-built tooling or spent hours onboarding and offboarding. In 2021 they started Infra (YC W21): access granted or revoked via an API or CLI, short-lived credentials, identity-provider integration like Okta, and a roadmap from Kubernetes to Postgres and SSH.
What happened
A year of quiet iteration with pilot teams ranging from five developers to public companies preceded the 2022-05-17 Launch HN. The architecture bet was that credentials should be signed by a central root of trust with a short time to live but verified at the destination infrastructure — no central proxy, no single point of failure, no proxying latency across regions, and access that keeps working if Infra's API or the identity provider is down. The launch drew 159 points and 58 comments: Teleport's CTO defended his product's proxy-based design, supporters welcomed a fully open-source core, and skeptics asked who would pay once the core was free.
No ending yet — it is still running.
Background
Infra is a YC W21 startup that bet the missing layer in infrastructure security was for teams too small for enterprise sales: an open-source tool to manage who can reach Kubernetes clusters, servers and databases, deployable by a five-person team without talking to a salesperson. The technical bet was equally deliberate: credentials are issued by a central root of trust with short lifetimes, but verified at the destination infrastructure rather than through a central proxy, so access is not hostage to a single point of failure.
Founders Jeff and Michael had already lived the lifecycle: they co-founded Kitematic, sold it to Docker, built Docker Desktop, then made Infra App, a Kubernetes client. What they kept hearing was access pain — large teams locked developers out entirely, small teams handed everyone admin, and the teams in between built in-house tooling or spent their days onboarding and offboarding. In 2021 they started building Infra under YC W21 and iterated quietly with pilot teams ranging from five developers to public companies.
Infra launched on Hacker News on 2022-05-17 with 159 points and 58 comments, including an extended architecture debate with Teleport's CTO over centralized proxies versus verifying credentials at the destination. The company planned to make money through a managed service priced by usage, leaving the open-source core free — and critics on the thread pressed exactly that question: if the core is fully open source, who pays? The repository remained live and unarchived, with about 1.5k stars at the 2026-09-05 snapshot; no later funding or shutdown event appears in the sources reviewed.
What has to be true
- The pain was structural: teams between "nobody gets access" and "everyone gets admin" had no option between hand-built tooling and enterprise products sold through sales contracts.
- The founders had the credibility of having built Docker Desktop, so Kubernetes teams recognized the product's lineage immediately.
- Verifying credentials at the destination instead of through a central proxy made reliability a feature: access survives an Infra outage, and multi-region users are not proxied.
- Making the core open source and free inverted the incumbent playbook, buying community goodwill while reserving the managed service as the paid tier.
What can be applied
Attack the segment incumbents' sales model excludes: a self-hostable open-source core let small teams adopt Infra without a sales call, with the managed service as the later upsell.
Aftermath
As of 2026-09-05, the infrahq/infra GitHub repository remains public and unarchived, its About line still describing Infra as authentication and access management for servers, clusters and databases, with the snapshot showing roughly 1.5k stars and 69 forks. The reviewed sources — the 2022 launch thread and the repository page — document no verified funding round, acquisition, or shutdown after launch, so this entry records the bet and the launch without asserting what the company is doing today.
Sources
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card