SSH Console opens SSO-authenticated, recordable sessions to any node on your tailnet — no client, no keys, no jump host.
On a machine without your keys — a colleague's laptop, a tablet, a kiosk? Log into the console and you're one click from any server you're authorized to reach.
Every console session is captured with identity attached. Watch replays from the audit log — no configuration required.
The console enforces exactly the policy your tailnet already has. No parallel permission system to drift out of sync.
Pagers go off while you're out. Borrow any browser, authenticate, run the fix — recorded, attributable, revocable.
Let a vendor into exactly one host, for exactly the window you grant, with the session recorded end to end.
Small check, big cluster. The console works on mobile browsers when SSH apps don't.
Compliance wants evidence, not stories. Sessions are replayable asciinema files tied to a person.
| OpenVLAN SSH (CLI) | SSH Console | |
|---|---|---|
| Authentication | SSO via tailnet identity | SSO via web login |
| Local client required | Yes (any SSH client) | None — browser |
| Session recording | In check mode | Always on |
| Best for | Everyday engineering work | Break-glass, mobile, vendor access |