Warpgate Bastion 0.29 adds just-in-time session approvals

Warpgate is a bastion-style PAM that needs neither a client app nor a server-side agent. It's a FOSS alternative to Teleport/StrongDM/Hashicorp Boundary: warpgate.null.page So... I've sent the last 1.5 months getting the session approvals to work just right to get a bit closer to feature parity with Teleport's enterprise edition. Admins can now set specific targets to require manual approvals and then the end user gets held up at the start of the connection until they get approved (with an optional grace period). I've sent quite a bit getting everything to work just right with clustering and polishing out various quirks like admin UI live updates not working cross-node and such. And another big thing is an optional MFA enforcement policy (forces end users to set up TOTP when they log in). My focus for the next release is going to be polishing and merging the Vault/OpenBao support (base PR contributed by the community 🙏) and (maybe) credential passthrough for SSH. Full release notes: github.com/warp-tech/warpgate/releases/tag/v0.29.0

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论