Consolidate identity-based access to Kubernetes clusters across all environments, self-hosted or in the Cloud. Meet compliance requirements, and have complete visibility into kubectl access and behavior.Get Started
Implement industry best practices for Kubernetes access with minimal configuration. Easily enforce MFA, RBAC, and SSO using identity-based short-lived X.509 certificates for engineers and service accounts.
Move away from vulnerable keys and passwords towards auto-expiring certificates for users and service accounts to access Kubernetes clusters.
Continuously maintain compliance and pass audits with minimal effort. The supported standards include SOC 2, FedRAMP, HIPAA, ISO 27001, PCI and more.
Track real-time activities and identify responsible actors through live session view, historical replays, and consolidated audit logs across all Kubernetes clusters.
You can access Kubernetes clusters running anywhere. From clouds and data centers to third party private networks behind NAT and firewalls.
Login once and easily switch between environments. No need to juggle passwords or hop between VPNs. Seamlessly use kubectl and other Kubernetes tools without compromises.
Auto-discover and enroll cloud hosted Kubernetes clusters for efficient and secure infrastructure scaling operations.
A single login provides engineers with frustration-free access to Kubernetes clusters across all environments.
With seamless integration of Kubernetes RBAC authorization resources, control access down to individual Kubernetes API groups, resources, and verbs.
Render credential exfiltration attacks useless by implementing hardware based multi-factor authorization for privileged operations like `kubectl exec`. Support for Apple TouchID, YubiKeys, or any PIV compatible device.
Move away from the default admin and cluster-admin roles with just-in-time Kubernetes privilege escalation for administrative and sensitive tasks. Build access approval workflows with Slack, PagerDuty, Jira, and more.
Implement moderated sessions, enforce concurrent session restrictions, proactive session termination and identity locking across your entire infrastructure footprint.
Every interactive kubectl session by an engineer or service account is recorded for future replay and can be audited and analyzed by other tools for behavior anomalies.
Eliminate provisioning headaches with Kubernetes Auto-Discovery for cloud hosted clusters.
Support for cloud Kubernetes clusters on AWS, Azure or GCP, as well as self-hosted clusters.
Seamless integration with existing workflows and tools like kubectl, Helm, Terraform, and more.
Teleport is a certificate authority and identity-aware, multi-protocol access proxy which implements protocols such as SSH, RDP, HTTPS, Kubernetes API, and a variety of SQL and NoSQL databases. It is completely transparent to client-side tools and designed to work with everything in today's DevSecOps ecosystem.