So I've considered this before, and I know it is coming from a good place. It seems great for the good times. At Clarify.io we use immutable infrastructure and we don't log in to boxes. Except when there are problems. And there are problems. Always.
You don't want to have to fight your way in in the middle of a disaster.
At Clarify.io we've considered having an on-login event fire when an admin uses SSH to log in to the box. This would schedule the server for termination within 24 hours. This gets you best of all worlds:
- Gives tools to debug and restore service when there is a failure
- Forces admins to not depend on SSH to bring a system up
- Replaces servers when they are potentially drifting
- Encourages a "cattle" mentality about the servers