You may also want to edit the title as "Tell HN: Teleport retiring Team plan" since as it currently is written it could be a question, or a blog post about you retiring your teleport team
You may also want to edit the title as "Tell HN: Teleport retiring Team plan" since as it currently is written it could be a question, or a blog post about you retiring your teleport team
We were using Teleport Team, which is being discontinued entirely. We could switch to self-hosting, but we'll probably just go back to SSH jump servers which are more straightforward to set up, and don't have the risk that the license will change again to become more restrictive.
I was looking for similar solutions a while back and finally settled on a WireGuard-based solution.
Tailscale looks very cool as well, but you did mention avoiding unnecessary risks.
I've also heard good things about Tailscale but I haven't personally used it
Tailscale definitely works a lot better from a pricing perspective and I like how they've put SSO in their premium pricing rather than enterprise, with SCIM being used for enterprise market segmentation instead.
That being said, AWS SSM to a bastion host, then using IAM auth for RDS and EKS will probably do most of what we need. Slightly more effort, but not so much more that it's a deal breaker.
Take a look at Tailscale. If you are all in on AWS then using SSM is solid but if you have general access or other cloud access then Tailscale can probably help you out there.