Tag: Zero Trust
All the articles with the tag "Zero Trust".

Teleport instead of a VPN: audited access to servers, Kubernetes, and databases
Teleport solves a different problem than NetBird or Cloudflare Tunnel: they give you network access, Teleport gives you audited access to a specific resource. We cover short-lived certificates instead of SSH keys and kubeconfig, session recording with tsh play, and resource-level RBAC — then wire up access to a test Kubernetes cluster with tsh kube login.

SPIFFE/SPIRE: cryptographic workload identity instead of static secrets
SPIFFE standardizes workload identity through short-lived SVID certificates, and SPIRE — its reference implementation — issues and rotates them via two-tier attestation (node + workload) with no pre-shared secret anywhere. We break down how it differs from external-secrets-operator, how federation works across clusters, and deploy SPIRE to fetch a real X.509-SVID for a test pod.

The Intervals.icu MCP server in Claude, behind Pomerium
How we connected the Intervals.icu MCP server to Claude and locked it behind Pomerium auth. Plus: how to build a dedicated Claude project and turn it into a personal coach with instructions.

NetBird: A Modern Zero Trust VPN
NetBird is a modern self-hosted Zero Trust VPN built on WireGuard: peer-to-peer connections, automatic NAT traversal, and simple access control with no single point of failure.