Engineering and DevOps
Reach the build server, not the whole cloud.
Engineers get direct encrypted paths to the hosts their rules grant, SSH in a tab when they are away from their machine, and everything as code: API users, access tokens and a Terraform provider.
What you get
Paths, sessions and code
- Direct pathsDevice to host, encrypted, opening on demand. No bastion to hop through, no concentrator in the way.
- SSH in a tabSecure Sessions open SSH and Telnet in the browser with a managed key, recorded.
- API usersService identities with access tokens; every object the Control Center manages is in the REST API.
- TerraformUsers, groups, rules, resources and settings as code, reviewed in a pull request.
Infrastructure
Clouds and clusters as networks
- Cloud networksA routing device in each VPC or VNet; routes granted to the groups that deploy there.
- Hosts with the agentServers join directly, as a service, enrolled with a key; no interactive sign-in.
- Private DNSInternal names resolve across environments without exposing them.
- Traffic LogsWhat each host talked to, with the rule that allowed it, when you want it.
On-premises
Run it yourself if you must
| Component | Delivery |
|---|---|
| Server, Control Center, Workspace, gateway | Container images, pinned by digest |
| Kubernetes | Helm charts and an operator |
| Agent | Packages built for your deployment |
| Session engine | A pinned sidecar reachable from the gateway only |
Questions buyers ask
Can we keep our existing SSH keys?
Yes. A Secure Session can use a managed key the administrator stored, or the person's own credential entered in the session page.
Is there an API for everything?
Yes. The REST API covers every object the Control Center manages; API users carry their own tokens and roles.