Servers, databases, and clusters — reachable by name, gated by identity, logged end to end.
One jump host per environment, each a pet with its own keys, patches, and breach radius.
Everyone SSHes as deploy@. When credentials leak, forensics can't tell people apart.
Every new team member means new allowlist entries across N devices — and offboarding never removes them all.
Nodes initiate outbound connections only. Nothing listens on a public port — there's no inbound surface to scan or exploit.
MagicDNS resolves prod-db-3 anywhere. Rebuild the box, the name follows the identity.
SSO-authenticated, recorded shell sessions with no SSH keys distributed at all. Check-in/check-out for the sensitive ones.
Who may reach what, expressed as reviewable policy in Git. Onboarding is one group membership; offboarding is its removal.
Colo racks and office servers join like laptops.
Or via subnet routers for whole VPC ranges.
Operator-managed access to nodes, pods, and the API.
Ephemeral runners with short-lived identities.