01
One account for the VPN
I have the VPN opened with the company account: no more VPN-specific password.
Cloud galaxy Case 6 of 7
The problem
What I did
01
I have the VPN opened with the company account: no more VPN-specific password.
02
I replace server access keys with temporary certificates tied to identity: nothing left to hand out.
03
If normal access refuses everything, a rescue console lets me take back control, without restarting a production gateway.
The result
We know who gets in, and when someone leaves, it is handled by removing one account.
Stack