Open osterman opened 6 years ago
I think stuff like this is better to implement on top of logging/alerting services. For example in 2.5.1 as a lambda function of dynamodb event hook.
Open to considering that. Depends on what the outcome looks like.
Here's something that 1Password for Teams supports out-of-the-box.
what
why
use case
One of our "best practices" is to promote a buddy system for accountability. Every SSH login is posted to a slack channel. Users should comment as to why they are accessing production systems. This should be acknowledged by another designated team member.
(screenshot from the
cloudposse/bastion
, which supports this)