Turn emails into revenue with Brew. No credit card, free credits to try.
goteleport.com · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
Teleport
New in Identity
Teleport — New in Identity - Issue #8
Most infrastructure teams already know what should replace static credentials and network-level access. The gap is not knowledge. Removing a shared credential means proving what depends on it first, and narrowing a VPN profile means maintaining rules that drift the moment they are written. This issue looks at three environments where the fix is well understood and still undone.
Teleport Identity Security for AI is now in preview. Fewer than 0.1% of employees are insider threats, but an agent that never sleeps and spawns its own subagents has to be treated like one by default. It constrains what agents can do through trusted runtimes and agentic classifiers, then ties every action back to the identity that started the delegation chain.
Read the Announcement →
Read the blog post →
Guide: Certificate-Based Authentication for Payment & Banking Infrastructure
By Chris De La Garza
Static credentials survive in payment infrastructure for a reason: the cost of removing one is immediate and measurable, while the security risk is not. Revoking a shared database password or an SSH key means verifying every pipeline dependency first, and an outage during peak processing hours is felt the same day. Audit logs scattered across dozens of systems carry no identity attribution in the meantime. The guide covers how certificate-based authentication, machine and workload identity, and hardware attestation replace those credentials across on-prem, cloud, and Kubernetes.
Read the full post →
Securing kubectl on Remote Kubernetes Clusters Without Static Credentials or VPNs
By Steve Martin
A fleet of five hundred edge devices running K3s means five hundred kubeconfig files, and every kubeconfig is a shared static credential. Exposing each API server to reach them turns that fleet into five hundred entry points into production. The workarounds fail for an operational reason: the customer owns the network perimeter those devices sit behind and has no reason to open inbound ports. Engineers still need kubectl to debug robots, drones, and sensors in the field, so the sprawl keeps growing.
Read the full post →
VPN Alternative for Internal Web Apps
By Sami Ali
Most VPN deployments run on a handful of coarse profiles like "engineering" or "all-staff", and inside a profile a user can reach every host and port it allows. Narrowing that per user or per app means maintaining firewall rules and network ACLs that drift over time, so it is usually left undone. The audit trail has the same problem: a VPN log records that someone connected from an IP at a time, not which internal app they opened or what they did inside it.
Read the full post →
Have questions or want to keep the conversation going? Join us in our Community Slack →
If you found this useful, pass it along to someone else who would, too.
Thanks for reading,
The Teleport Editorial Team
P.S. We'll be at these events over the next few weeks. Come find us.
Sep 1: KCD SF -- Mountain View, USA
Sep 7: CPX GISEC -- Dubai
Sep 15-17: AI Infra Summit -- Santa Clara, USA - Ev will be speaking!
Sep 16-17: DCD Connect London
Sep 24: (A)Identity Day - London
Find us near you →
Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612
If you no longer wish to receive these emails anymore, click on the following link:
UNSUBSCRIBE
TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY