Skip to main content

Teleport

Identity-aware access platform that issues short-lived certificates for SSH, Kubernetes, database, RDP, and web application access with session recording and audit.

Technical Architecture & Overview

Teleport is an identity-aware access platform that provides connectivity, authentication, access controls, and audit for infrastructure. It combines a built-in certificate authority that issues short-lived certificates, a unified access-control layer, and reverse-tunneling so users and machines can reach SSH, Kubernetes, database, RDP, web application, and cloud API resources without long-lived keys, VPNs, or bastion hosts.

Targeted Technical Use Cases

Replacing static credentials and VPNs with a single identity-based access and audit layer for heterogeneous cloud and on-prem infrastructure.

Evaluation & Trade-offs

Core Strengths

  • +Short-lived, certificate-based authentication eliminates shared SSH keys, Kubernetes tokens, and database passwords.
  • +Unified access control across SSH, Kubernetes, RDP, HTTPS, database protocols, and cloud APIs behind one RBAC layer.
  • +Protocol-level session recording and audit across SSH, Kubernetes, databases, RDP, and web sessions.

Trade-Offs & Limitations

  • -The teleport server daemon runs on Linux only; macOS and Windows are limited to client and admin tools.
  • -Community Edition SSO is limited to GitHub; OIDC, SAML, and Okta require Enterprise licensing.
  • -Machine and Workload Identity certificates cannot exceed 24 hours and are incompatible with per-session MFA.

Defensive Security Application

Removing standing access by replacing static credentials with short-lived, identity-bound certificates and recording every session for forensic review.

Frequently Asked Questions

What is Teleport?

Teleport is an identity-aware access platform that provides connectivity, authentication, access controls, and audit for infrastructure. It combines a built-in certificate authority that issues short-lived certificates, a unified access-control layer, and reverse-tunneling so users and machines can reach SSH, Kubernetes, database, RDP, web application, and cloud API resources without long-lived keys, VPNs, or bastion hosts.

What is Teleport used for?

Replacing static credentials and VPNs with a single identity-based access and audit layer for heterogeneous cloud and on-prem infrastructure.

What are the strengths of Teleport?
  • +Short-lived, certificate-based authentication eliminates shared SSH keys, Kubernetes tokens, and database passwords.
  • +Unified access control across SSH, Kubernetes, RDP, HTTPS, database protocols, and cloud APIs behind one RBAC layer.
  • +Protocol-level session recording and audit across SSH, Kubernetes, databases, RDP, and web sessions.
What are the limitations of Teleport?
  • +The teleport server daemon runs on Linux only; macOS and Windows are limited to client and admin tools.
  • +Community Edition SSO is limited to GitHub; OIDC, SAML, and Okta require Enterprise licensing.
  • +Machine and Workload Identity certificates cannot exceed 24 hours and are incompatible with per-session MFA.
How is Teleport used defensively?

Removing standing access by replacing static credentials with short-lived, identity-bound certificates and recording every session for forensic review.