Skip to content

Feedback issue for Teleport for rollout

We are working on rolling out Teleport for managing time based SSH access as part of OKRs to reduce the number of people who have continuous access to the GitLab.com production environment. The current focus has been to limit the number of users who have ssh keys registered in data_bags with chef. Instead, we can use Teleport to provide time based access with an approval workflow in slack.

This issue is meant to be a gathering point for feedback as we roll things out. @devin and @dawsmith can be tagged as DRIs.

  1. Runbook to try Teleport for rails-consoles
  2. Runbook to try Teleport for db-consoles

Note that there are differences - staging no longer requires approval (all backend engineers have this as an role entitlement). Production does still require approval from infrastructure. The current idea would be to directly mention someone on your request post in #infrastructure-lounge if you haven't been approved quickly.