Ask HN: How are you protecting your staging environment(s) for your web apps?
By "staging environment" I'm referring to any non-production environment that you need to access over HTTPS, either ephemeral or long-living and potentially shared.
Are you using basic auth? If so, how are you managing usernames & passwords?
Are you using a VPN?
Are you using something else?