from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Teleport

Ideas, decisions, and lessons from the team.

goteleport.com (opens on the source site)LinkedIn X
14Posts tracked
5 days agoLatest publication
1.2Posts / month over the last 12 months

Latest writing

14 of 14 posts

How to Reduce Overprivileged Kubernetes Service Accounts (opens on the source site)

IN THIS BLOG Overprivileged Kubernetes ServiceAccounts persist when broad RBAC, cloud IAM permissions, and long-lived credentials outlive their intended use. Reduce overprivileged access with least privileged RBAC, scoped cloud permissions, and short-lived certificates that eliminate static credentials. I spent two days last quarter tracking down why a developer could delete production secrets. The RBAC looked fine. The ClusterRoleBinding said edit, not cluster-admin. But someone had bound the default service account to cluster-admin permissions in a CI namespace three years ago, and that…

Read at the source

SSO-Backed kubectl Access Across Many Clusters (opens on the source site)

TL;DR: If your development, staging, and production API servers all trust the same OIDC issuer and audience, Kubernetes will accept the same cached kubectl token across all of them. You should use separate audiences in your API. One Company Login for Development, Staging, and Production A platform team manages three Kubernetes clusters: development, staging, and production. Each cluster has an API server, the Kubernetes component that receives kubectl requests.** The team connects all three API servers to the company login service, so Alice can sign in with her usual work account. Now Alice…

Read at the source

How to Eliminate Shared Production Kubeconfigs (opens on the source site)

TL;DR: A production kubeconfig that contains a certificate or token is a production credential, and every copy then accesses the cluster with the same identity. You should use individual single sign-on (SSO) logins and short-lived credentials for your clusters. What the Kubeconfig Actually Controls Let's use a k3d cluster to parse the file. First, read the kubeconfig from disk: cat ~/.kube/config The file looks like this, with the encoded data shortened: apiVersion: v1 kind: Config current-context: k3d-lms-cluster clusters: - name: k3d-lms-cluster cluster: certificate-authority-data:…

Read at the source

FIPS 140-2 vs FIPS 140-3, Explained (opens on the source site)

Read this article to learn: Key differences between FIPS 140-2 and FIPS 140-3 The exact FIPS 140-2 to FIPS 140-3 transition dates, as described by NIST How to read a real CMVP certificate How FIPS 140-3 affects your infrastructure What is FIPS 140-3? FIPS 140-3 is the current standard for validating cryptographic modules, which are the specific hardware or software components that implement encryption and manage keys inside a defined boundary. FIPS 140-3 was approved on March 22, 2019, became effective on September 22, 2019, and supersedes FIPS 140-2, which dates back to 2001. Most FIPS 140-3…

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.