# One account opens every access

Cloud galaxy · Cédric Merlin, CTO · https://merlin-cedric.fr/en/cloud/acces/

A VPN opened with the company account, temporary certificates and a rescue console: we always know who gets in.

## The problem

Too many accesses (VPN, servers, consoles), and too many passwords and keys passed around between people.

## What I did

1. **One account for the VPN.** I have the VPN opened with the company account: no more VPN-specific password.
2. **Temporary access.** I replace server access keys with temporary certificates tied to identity: nothing left to hand out.
3. **A console as a rescue.** If normal access refuses everything, a rescue console lets me take back control, without restarting a production gateway.

## The result

We know who gets in, and when someone leaves, it is handled by removing one account.

## Stack

Identity-based access, VPN, Ephemeral certificates, Rescue console

---
Page: https://merlin-cedric.fr/en/cloud/acces/ · Contact: contact@merlin-cedric.fr
