← CloudCédric MerlinFREN

Cloud galaxy Case 6 of 7

One account opens every access

The problem

Too many accesses (VPN, servers, consoles), and too many passwords and keys passed around between people.

What I did

01

One account for the VPN

I have the VPN opened with the company account: no more VPN-specific password.

02

Temporary access

I replace server access keys with temporary certificates tied to identity: nothing left to hand out.

03

A console as a rescue

If normal access refuses everything, a rescue console lets me take back control, without restarting a production gateway.

Diagram: from a ring of keys to a single accountA ring of six keys melts into a company account badge. The account opens the VPN, then a temporary certificate is issued to the server. When normal access refuses everything, a console cable reaches the server directly, without restarting the production gateway.accountcompanyephemeralidentityVPNaccess deniedconsolegatewayno restart

The result

We know who gets in, and when someone leaves, it is handled by removing one account.

Stack

  • Identity-based access
  • VPN
  • Ephemeral certificates
  • Rescue console