Infrastructure access

Servers, databases, and clusters — reachable by name, gated by identity, logged end to end.

The status quo hurts

Bastion sprawl

One jump host per environment, each a pet with its own keys, patches, and breach radius.

Shared service accounts

Everyone SSHes as deploy@. When credentials leak, forensics can't tell people apart.

Firewall ticket roulette

Every new team member means new allowlist entries across N devices — and offboarding never removes them all.

The OpenVLAN pattern

Every host dials out

Nodes initiate outbound connections only. Nothing listens on a public port — there's no inbound surface to scan or exploit.

Names, not IPs

MagicDNS resolves prod-db-3 anywhere. Rebuild the box, the name follows the identity.

OpenVLAN SSH

SSO-authenticated, recorded shell sessions with no SSH keys distributed at all. Check-in/check-out for the sensitive ones.

ACLs as code

Who may reach what, expressed as reviewable policy in Git. Onboarding is one group membership; offboarding is its removal.

Works with your estate

Bare metal

Colo racks and office servers join like laptops.

Cloud VMs

Or via subnet routers for whole VPC ranges.

Kubernetes

Operator-managed access to nodes, pods, and the API.

Containers & CI

Ephemeral runners with short-lived identities.

Retire the bastion this quarter