Skip to content

Evaluate Hashicorp Boundary for rails console access and auditing

In addition to Gravitational's Teleport, we should also investigate Hashicorp's Boundary to control access to kubernetes clusters.

Architecture Diagram

Criteria

We will use the criteria established here: https://gitlab.com/gitlab-com/gl-infra/infrastructure/-/issues/11729

  • Infra group or security group can approve access without much friction
  • Full session audit record with session playback
  • Time based access - No developer entitlements by role
  • No Chef data bags
Edited by Devin Sylva