
Stop Giving Permanent Access To Anyone: Just-in-Time with Apono
Source: YouTube · DevOps & AI Toolkit · published Sep 11, 2023 · 25:06
The video explores Apono as a solution for managing just-in-time access to Kubernetes clusters during break glass scenarios 0:17, concluding it excels at temporary access management but has limitations with Kubernetes resource handling 24:49.
Key Takeaways:
• Avoid direct system access except for emergency "break glass" scenarios 0:17-1:15
• Apono enables temporary permissions for specific resources during limited time periods 2:33-2:57
• Apono has Kubernetes limitations: hardcoded resource definitions and poor understanding of relationships 7:23-7:39
• Effective for temporary access but lacks CLI/API for management and is SaaS-only 22:06-23:03
Apono works best when focused strictly on just-in-time access management rather than trying to define permissions and roles 24:49-24:51.
Sources:
- 0:17-1:15 Why direct access should be avoided
- 2:33-2:57 Apono as JIT access solution
- 7:23-7:39 Kubernetes limitations critique
- 22:06-23:03 CLI/API limitations and SaaS-only model
- 24:49-24:51 Conclusion on Apono's scope
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hi hey what do you want uh can you give me a XIs cluster no go away [Music] let me ask you a question what is the best way to give people access to a kubernetes cluster specific resources in that cluster AWS accounts databases or any other parts of the system well no one should have direct access to anything we have pipelines githubs grafana and a bunch of other tools that are very very good at managing the system and provide insights into what's going on in that system from there on Argo CD flux GitHub actions Jenkins and any other tool will take care of the rest if you need to know what's going on or to debug any issue you can open grafana Jagger Prometheus or any other observability tool giving you direct access to the system is a recipe for disaster so no human should have direct acces…