wilmaethqn44
Member
OP
- Joined:
- Jun 2024
- Posts:
- 135
- From:
- Cardiff, UK
Hi everyone, sorry for the silly question but our little agency is growing and I'm getting worried about how we manage server access. Right now we just share a few passwords for root and I know thats probably bad
We have maybe 6 client servers on InterServer and some old boxes at Hostinger. Me and my business partner need to both get in, plus sometimes a freelancer. I keep hearing about SSH keys but I dont really understand how to do this for a team without giving everyone everything.
Is there a simple tool for this? I looked at some enterprise stuff and it was way too much. We are two people. I feel silly asking but I dont want to break a client site.
Thanks for any advice
frames, tables, still valid HTML
Doug
Member
New Jersey
- Joined:
- Jul 2024
- Posts:
- 271
- From:
- New Jersey, US
"team" of two people, six shared passwords, asking about "scalable access control"
grabs popcorn, checks /r/drama
sofialund
Member
homelab heatstroke
- Joined:
- Jul 2024
- Posts:
- 140
- From:
- Buenos Aires, Argentina
¡the tool simple exists my friend!
For the team small I recommend the Vault of HashiCorp or the Teleport of Gravitational! The keys SSH centralizan in server the central. The access you control with the roles.
¡but careful! The setup initial is complex a bit. For the team of two persons maybe the manual the key is sufficient. The server each with the key own and the sudo configure careful.
The password shared is the danger the big. ¡change immediate!
The Vault free has tier for the users 25. Very generous is. The audit logs have. The compliance the clients helps much.
¡the question not is silly! The security is important always.
hot air, steady hand, magic smoke
pauloserver
Member
- Joined:
- Jun 2024
- Posts:
- 117
- From:
- São Paulo, Brazil
Shared passwords for root is rough, I did that once
chill infrastructure for chill people 🦫
wilmaethqn44
Member
OP
- Joined:
- Jun 2024
- Posts:
- 135
- From:
- Cardiff, UK
Ok ok I get it its bad! But I looked at HashiCorp Vault and I dont even know what a token is. Is there something between "shared password" and "enterprise devops toolchain"?
frames, tables, still valid HTML