Operational consequence
A leaked key or compromised endpoint creates durable blast radius, while logs cannot reliably connect request, approver, device, credential, and session outcome.
DEVOPS PRODUCTION ACCESS
Scope infrastructure access by person, qualified device, resource, role, protocol, approval, and time, then correlate the resulting session evidence.
System role: Customer solution owner + Oten solution architecture
Evaluation depends on: Requires a bounded component, platform, protocol, integration, migration, rollback, and evidence scope.
Platform, SRE, database, Kubernetes, and infrastructure teams that reach production through standing accounts, shared keys, bastions, or chat-based approval.
Long-lived credentials and always-on roles remain useful after the original task or approval has ended.
A leaked key or compromised endpoint creates durable blast radius, while logs cannot reliably connect request, approver, device, credential, and session outcome.
JIT authority is issued for the approved resource, role, protocol, and time from a device that satisfies the resource's current policy.
Define the subject, device, resource, protocol, policy version, enforcement points, confirmation requirement, and recovery owner.
Select the resource, role, reason, protocol, and duration.
Apply separation of duty, expiry, identity assurance, and device requirements.
Create protocol-appropriate short-lived authority without exposing a standing secret where supported.
Enforce at the Endpoint and Gateway or protocol boundary.
Correlate request, approval, policy, credential, session, outcome, and expiry.
Oten Endpoint, Access Control Plane, Oten Gateway with the required protocol handler, identity services, and credential or certificate integration.
Identity provider, approval or ITSM system, certificate authority or vault, SSH, databases, Kubernetes, RDP or web administration, and audit storage.
Credential issue, injection, renewal, recording, revoke, and active-session termination differ by protocol and connection mode.
Map accounts, keys, roles, bastions, resource owners, and emergency paths.
Pilot a resource and protocol without removing the recovery path.
Rotate credentials and reduce role lifetime after the JIT path is proven.
Test stronger authentication, notification, audit, expiry, and post-event review.
Next in Oten Access
Define success, limitation, failure, recovery, and rollback evidence before changing the production access boundary.