> I fully expect this to be a bit of an uphill sell to people. Writing stuff that mucks with the authentication stack is rightfully kinda scary, and there will need to be a lot of security and subject matter expert review. I expect this to be a slow burn, but good god I would love to see it happen.
Actually using it would be a long ways off, but I don't think conceptually it's a hard sell. I'm interested in making authentication easier for my developers lately, and also in dodging some key management in favor of accounts people already have at work. Right now, I'm evaluating Tailscale for VPN access, since I find myself supporting developers without (yet) any remote access to them or any endpoint management crap on their machines, and walking them through configuring WireGuard has proven painful (more painful than I expected, which maybe sounds dumb). (Incidentally, ‘Tailscale’ is a name I remembered as a possible VPN solution because I think your blog is good.)
One of the things that's occurred to me during my testing is that if it could be as stunningly easy to configure as Tailscale, it'd be great to use some kind of SSH gateway that plugged into everyone's SSO instead of managing a bunch of SSH keys. Plus, being able to have admins confirm privilege escalation requests might make it easier for me to convince some higher-ups to give the developers I support sudo rights.
There are products that support things like this, but I think the use case is a natural extension of what people are likely already using Tailscale for, and it would be a killer feature to integrate.