# Teleport

Recent content in The Teleport Blog

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## FIPS 140-2 vs FIPS 140-3, Explained

DevFeed: [FIPS 140-2 vs FIPS 140-3, Explained](<https://devfeed.tech/articles/fips-140-2-vs-fips-140-3-explained-29647.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/fips-140-2-vs-fips-140-3-explained/>)

Author: info@goteleport.com (Mayur Pipaliya)

Published: 2026-09-09T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [fips 140-3](<https://devfeed.tech/topics/fips-140-3.md>), [FIPS validation](<https://devfeed.tech/topics/fips-validation.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article explains the differences between FIPS 140-2 and FIPS 140-3, including the standards' origins, CMVP validation certificates, applicable requirements for protecting sensitive data, and the transition timeline through September 2026.

### Source excerpt

Understand key changes from FIPS 140-2 to FIPS 140-3.

## ISO 42001 Evidence: What Auditors Ask For

DevFeed: [ISO 42001 Evidence: What Auditors Ask For](<https://devfeed.tech/articles/iso-42001-evidence-what-auditors-ask-for-29720.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/iso-42001-audit-evidence/>)

Author: info@goteleport.com (Preet Dhatt)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [audit](<https://devfeed.tech/topics/audit.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [article](<https://devfeed.tech/tags/article.md>), [audit](<https://devfeed.tech/tags/audit.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iso](<https://devfeed.tech/tags/iso.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [requirements](<https://devfeed.tech/tags/requirements.md>)

### AI overview

This article explains what auditors look for in ISO 42001 evidence and how organizations can connect access, approvals, infrastructure, CI/CD activity, releases, and production changes into an evidence trail. It also discusses monitoring, human oversight, third-party access, and data governance within an AI Management System.

### Source excerpt

Prepare ISO 42001 audit evidence that proves your controls work in practice.

## Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

DevFeed: [Identity Everywhere: Bringing Infrastructure Identity to Agentic IT](<https://devfeed.tech/articles/identity-everywhere-bringing-infrastructure-identity-to-agentic-it-29604.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/cisco-teleport-partnership/>)

Author: info@goteleport.com (Peter Bailey, Ev Kontsevoy)

Published: 2026-08-25T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Cisco](<https://devfeed.tech/topics/cisco.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Cisco and Teleport announce a strategic partnership involving technology integration, licensing, and investment. The article presents Infrastructure Identity as a cryptographic model intended to connect secure identity with human and machine actions, including activity by workloads, automation, and AI agents.

### Source excerpt

Cisco and Teleport are announcing a strategic partnership centered on deep technology integration, licensing, and investment.

## We Had 13 Engineers Spend Three Months Finding Vulnerabilities with LLMs

DevFeed: [We Had 13 Engineers Spend Three Months Finding Vulnerabilities with LLMs](<https://devfeed.tech/articles/we-had-13-engineers-spend-three-months-finding-vulnerabilities-with-llms-29646.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/finding-vulnerabilities-with-llms/>)

Author: info@goteleport.com (Rob Picard)

Published: 2026-08-19T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [llms](<https://devfeed.tech/tags/llms.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Teleport describes how 13 software engineers spent a quarter using frontier LLMs and coding agents to review an existing codebase, find vulnerabilities, triage findings, and fix bugs. The article reports that simple prompting of an LLM at one codebase component performed better than a complicated multi-stage agentic harness in their experiments.

### Source excerpt

Our approach to "pressure washing" our codebase using frontier LLMs.

## How to Prevent RBAC Role Explosion with Nested Access Lists

DevFeed: [How to Prevent RBAC Role Explosion with Nested Access Lists](<https://devfeed.tech/articles/how-to-prevent-rbac-role-explosion-with-nested-access-lists-29805.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/role-explosion-rbac-nested-access-lists/>)

Author: info@goteleport.com (Paul Curtis)

Published: 2026-08-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Access Control](<https://devfeed.tech/topics/access-control.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [development](<https://devfeed.tech/tags/development.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [teams](<https://devfeed.tech/tags/teams.md>)

### AI overview

This tutorial explains RBAC role explosion, how repeated role changes create inflexible and duplicated roles, and how nested access lists can apply inherited permissions while keeping roles fixed.

### Source excerpt

Learn how to use access lists to prevent RBAC role explosion.

## Navigating SAMA, ADGM & DFSA Requirements with Teleport

DevFeed: [Navigating SAMA, ADGM & DFSA Requirements with Teleport](<https://devfeed.tech/articles/navigating-sama-adgm-dfsa-requirements-with-teleport-29812.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/sama-adgm-dfsa-compliance/>)

Author: info@goteleport.com (Mukund Cadambi)

Published: 2026-08-12T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Requirements](<https://devfeed.tech/topics/requirements.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how SAMA, ADGM, and DFSA requirements affect cloud service providers operating in Saudi Arabia and the UAE. It describes challenges involving data sovereignty, cybersecurity, identity and access controls, privileged and third-party access, and audit evidence, and presents a unified identity layer as an approach to operationalizing compliance.

### Source excerpt

Learn how Teleport helps CSPs meet SAMA, ADGM, and DFSA compliance.

## How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go's SSH Library

DevFeed: [How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go's SSH Library](<https://devfeed.tech/articles/how-two-small-bugs-led-to-a-critical-vulnerability-and-a-cryptography-audit-of-go-s-ssh-library-29769.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/ncc-cryptography-audit-go-ssh/>)

Author: info@goteleport.com (Rob Picard)

Published: 2026-08-10T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cryptographic audit](<https://devfeed.tech/topics/cryptographic-audit.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [audit](<https://devfeed.tech/tags/audit.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [cryptographic-audit](<https://devfeed.tech/tags/cryptographic-audit.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [go](<https://devfeed.tech/tags/go.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Teleport describes a critical vulnerability caused by two interacting bugs in its SSH certificate validation logic and reports that NCC Group conducted a cryptographic audit of Go's SSH package. The audit resulted in nine CVEs and identified subtle issues requiring expert review.

### Source excerpt

Learn about NCC Group's cryptographic audit of Go's SSH package.

## How to Use GitHub Actions to Deploy to Kubernetes Without Shared Secrets

DevFeed: [How to Use GitHub Actions to Deploy to Kubernetes Without Shared Secrets](<https://devfeed.tech/articles/how-to-use-github-actions-to-deploy-to-kubernetes-without-shared-secrets-29816.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/secretless-github-actions-for-kubernetes/>)

Author: info@goteleport.com (Noah Stride)

Published: 2026-08-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This tutorial explains how to use Teleport and GitHub Actions to deploy applications to Kubernetes without shared, long-lived credentials. It covers short-lived identities, Kubernetes RBAC, Teleport roles, and join tokens, and discusses extending the approach to database connections and internal APIs.

### Source excerpt

Learn how use GitHub Actions to deploy to Kubernetes using short-lived, verifiable identities.

## Guide: Certificate-Based Authentication for Payment & Banking Infrastructure

DevFeed: [Guide: Certificate-Based Authentication for Payment & Banking Infrastructure](<https://devfeed.tech/articles/guide-certificate-based-authentication-for-payment-banking-infrastructure-29601.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/certificate-based-authentication-payment-banking/>)

Author: info@goteleport.com (Chris De La Garza)

Published: 2026-07-31T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [databases](<https://devfeed.tech/tags/databases.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [guide](<https://devfeed.tech/tags/guide.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This guide explains the challenges of static credentials in payment and banking infrastructure and presents certificate-based authentication as an approach for managing machine and workload identity. It covers on-premises, cloud, and Kubernetes environments, including hardware attestation.

### Source excerpt

A guide to certificate-based authentication in payment infrastructure.

## VPN Alternative for Internal Web Apps | Teleport

DevFeed: [VPN Alternative for Internal Web Apps | Teleport](<https://devfeed.tech/articles/vpn-alternative-for-internal-web-apps-teleport-29548.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/access-apps-without-vpn/>)

Author: info@goteleport.com (Sami Ali)

Published: 2026-07-24T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [identity-aware-proxy](<https://devfeed.tech/tags/identity-aware-proxy.md>), [security](<https://devfeed.tech/tags/security.md>), [vpn](<https://devfeed.tech/tags/vpn.md>), [web](<https://devfeed.tech/tags/web.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

### AI overview

This guide explains why VPN-based access to internal web applications becomes difficult to manage as organizations grow. It presents an identity-aware proxy as an alternative that authenticates users to individual applications, enforces per-application authorization, and provides an audit trail tied to named identities.

### Source excerpt

Replace VPN access to internal web apps with an identity-aware proxy: one login, one audit trail, and per-app access for every user.

## Identity Security for AI

DevFeed: [Identity Security for AI](<https://devfeed.tech/articles/identity-security-for-ai-29705.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/identity-security-for-ai/>)

Author: info@goteleport.com (Ben Arent)

Published: 2026-07-21T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security for AI](<https://devfeed.tech/topics/security-for-ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [github](<https://devfeed.tech/tags/github.md>), [identity](<https://devfeed.tech/tags/identity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [llms](<https://devfeed.tech/tags/llms.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-for-ai](<https://devfeed.tech/tags/security-for-ai.md>)

### AI overview

The article examines identity-security challenges created by AI agents that can act continuously with delegated access. It connects traditional risks such as broad permissions, credential sprawl, insider threats, and long-lived secrets with emerging risks from agents, sub-agents, and LLM capabilities, and advocates delegated, ephemeral, least-privilege access.

### Source excerpt

AI agents run 24/7 with the same infrastructure access as your engineers. See how Teleport secures AI with cryptographic identity, audit, and trusted runtimes.

## Securing kubectl on Remote Kubernetes Clusters Without Static Credentials or VPNs

DevFeed: [Securing kubectl on Remote Kubernetes Clusters Without Static Credentials or VPNs](<https://devfeed.tech/articles/securing-kubectl-on-remote-kubernetes-clusters-without-static-credentials-or-vpns-29735.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/kubectl-remote-clusters/>)

Author: info@goteleport.com (Steven Martin)

Published: 2026-07-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Kubernetes clusters](<https://devfeed.tech/topics/kubernetes-clusters.md>), [k3s](<https://devfeed.tech/topics/k3s.md>), [Network](<https://devfeed.tech/topics/network.md>), [Networks](<https://devfeed.tech/topics/networks.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [clusters](<https://devfeed.tech/tags/clusters.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [k3s](<https://devfeed.tech/tags/k3s.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-clusters](<https://devfeed.tech/tags/kubernetes-clusters.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [remote](<https://devfeed.tech/tags/remote.md>)

### AI overview

A guide to securing kubectl access to remote Kubernetes clusters running on distributed edge devices. It explains how NAT, firewalls, kubeconfig sprawl, and static credentials create access and security risks, and discusses avoiding publicly exposed API servers and VPN-related operational challenges.

### Source excerpt

Learn how to secure Kubernetes access across remote fleets without creating risk.

## How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

DevFeed: [How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate](<https://devfeed.tech/articles/how-teleport-operationalizes-the-eu-cyber-resilience-act-s-secure-by-design-mandate-29639.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-cra-secure-by-design/>)

Author: info@goteleport.com (Maximilian Heck, Waldemar Kindler)

Published: 2026-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Monitoring & Alerting](<https://devfeed.tech/topics/monitoring-alerting.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cra-requirements](<https://devfeed.tech/tags/cra-requirements.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [monitoring-alerting](<https://devfeed.tech/tags/monitoring-alerting.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how Teleport maps its infrastructure identity, access, policy, logging, monitoring, and audit controls to ENISA's Secure by Design and Default Playbook and the EU Cyber Resilience Act. It highlights cryptographic identity, least privilege, secure communication, supply-chain controls, and default protection of device identities and secrets.

### Source excerpt

See how Teleport features map to ENISA's Secure-by-Design specification for CRA.

## Keeping AI Workshop Content Current as Tools Change

DevFeed: [Keeping AI Workshop Content Current as Tools Change](<https://devfeed.tech/articles/the-room-where-v2-happens-29806.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/room-where-v2-happens/>)

Author: info@goteleport.com (Kathleen Sikora)

Published: 2026-07-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Automation](<https://devfeed.tech/topics/automation.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [claude](<https://devfeed.tech/tags/claude.md>), [training](<https://devfeed.tech/tags/training.md>), [workshop](<https://devfeed.tech/tags/workshop.md>)

### AI overview

An internal AI workshop had to be revised repeatedly after Claude's skills feature cleared approval between two sessions. The experience led the author to treat workshop content as iterative and to rely on participants' shared knowledge of prompts, workarounds, and workflows.

### Source excerpt

I taught the same AI workshop twice in one week, and half my material was already wrong by round two. Here's what that taught me about training on a moving target.

## When AI Agents Call AWS, Who Does AWS Think They Are?

DevFeed: [When AI Agents Call AWS, Who Does AWS Think They Are?](<https://devfeed.tech/articles/when-ai-agents-call-aws-who-does-aws-think-they-are-29559.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/ai-agents-aws-agentcore/>)

Author: info@goteleport.com (Jeffrey Ellin)

Published: 2026-07-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Amazon Bedrock AgentCore](<https://devfeed.tech/topics/amazon-bedrock-agentcore.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [MCP](<https://devfeed.tech/topics/mcp.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [amazon-bedrock-agentcore](<https://devfeed.tech/tags/amazon-bedrock-agentcore.md>), [aws](<https://devfeed.tech/tags/aws.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [iam](<https://devfeed.tech/tags/iam.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [s3](<https://devfeed.tech/tags/s3.md>)

### AI overview

This tutorial explains how to propagate a verified caller identity through an AI agent, Amazon Bedrock AgentCore, Lambda, and AWS API calls. It uses short-lived Teleport JWTs so downstream tools can associate requests with the authenticated user and improve accountability in CloudTrail.

### Source excerpt

Learn how to use Teleport JWTs to give MCP tools a verified identity in Amazon Bedrock AgentCore.

## Kubernetes for Agentic AI: Best Practices for Identity and Access

DevFeed: [Kubernetes for Agentic AI: Best Practices for Identity and Access](<https://devfeed.tech/articles/kubernetes-for-agentic-ai-best-practices-for-identity-and-access-29737.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/kubernetes-agent-identity-access/>)

Author: info@goteleport.com (Boris Kurktchiev, Megan Moore)

Published: 2026-07-07T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [audit](<https://devfeed.tech/topics/audit.md>), [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [agent-identity](<https://devfeed.tech/tags/agent-identity.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [audit](<https://devfeed.tech/tags/audit.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [identity](<https://devfeed.tech/tags/identity.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

This article explains when autonomous or long-running agents in Kubernetes need distinct workload identities instead of inheriting a user's identity. It recommends least-privilege access, short-lived credentials, re-authentication for sensitive actions, network enforcement, and auditability.

### Source excerpt

When agents act autonomously beyond a user's session, they need their own identity, least-privilege access, and full audit trails.

## How to Meet EU Cyber Resilience Act (CRA) Requirements

DevFeed: [How to Meet EU Cyber Resilience Act (CRA) Requirements](<https://devfeed.tech/articles/how-to-meet-eu-cyber-resilience-act-cra-requirements-29640.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-cyber-resilience-act/>)

Author: info@goteleport.com (Maximilian Heck, Waldemar Kindler)

Published: 2026-07-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Security](<https://devfeed.tech/topics/security.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eu](<https://devfeed.tech/tags/eu.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [requirements](<https://devfeed.tech/tags/requirements.md>)

### AI overview

This tutorial explains how identity, access, encryption, and audit controls relate to EU Cyber Resilience Act requirements. It also discusses fragmented security toolchains, a compromised Trivy release, and infrastructure patterns such as short-lived cryptographic identities, hardware-rooted device trust, and unified audit trails.

### Source excerpt

Learn how to implement identity, access, and audit controls that meet EU Cyber Resilience Act compliance requirements.

## PostgreSQL: How to Control and Audit Agent Access with Identity

DevFeed: [PostgreSQL: How to Control and Audit Agent Access with Identity](<https://devfeed.tech/articles/postgresql-how-to-control-and-audit-agent-access-with-identity-29789.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/postgresql-control-audit-agent-access/>)

Author: info@goteleport.com (Megan Moore)

Published: 2026-06-26T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [audit](<https://devfeed.tech/topics/audit.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [audit](<https://devfeed.tech/tags/audit.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>)

### AI overview

This article explains that PostgreSQL cannot identify AI agents as distinct actors because they authenticate as database roles. It describes the resulting access-control and audit risks, including broad permissions, non-deterministic query behavior, and long-lived service-account credentials, and introduces short-lived, task-scoped access as an alternative.

### Source excerpt

PostgreSQL cannot distinguish an AI agent as a distinct actor. Here's how that impacts access control, and what DBAs can do about it.

## Your AI Agent Needs to Know Who You Are

DevFeed: [Your AI Agent Needs to Know Who You Are](<https://devfeed.tech/articles/your-ai-agent-needs-to-know-who-you-are-29981.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/your-ai-agent-needs-to-know-who-you-are/>)

Author: info@goteleport.com (Jeffrey Ellin)

Published: 2026-06-24T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [audit](<https://devfeed.tech/topics/audit.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [identity](<https://devfeed.tech/tags/identity.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [mcp](<https://devfeed.tech/tags/mcp.md>)

### AI overview

The article explains that MCP tools typically see only the calling AI agent, not the human who initiated a request. It describes using short-lived, cryptographically signed Teleport JWTs to carry verified user identity through agent requests, enabling more precise authorization and more useful audit trails.

### Source excerpt

Learn how Teleport JWTs propagate human identity through MCP tool calls for audit, authorization, and access control.

## Automating Identity and Access for FedRAMP 20x KSIs with Teleport

DevFeed: [Automating Identity and Access for FedRAMP 20x KSIs with Teleport](<https://devfeed.tech/articles/automating-identity-and-access-for-fedramp-20x-ksis-with-teleport-29580.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/automating-identity-access-fedramp-20x/>)

Author: info@goteleport.com (Nicolas Morris)

Published: 2026-06-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how FedRAMP 20x changes identity and access compliance toward persistent validation using machine-readable evidence. It describes how unified identity management and audit trails can help address gaps in machine-to-machine authentication and continuous KSI validation.

### Source excerpt

Learn how to automate identity and access for FedRAMP 20x KSIs with a unified audit trail for identities, access, and persistent evidence.

## SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8

DevFeed: [SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8](<https://devfeed.tech/articles/soc-2-controls-for-non-human-identities-cc6-cc7-and-cc8-29856.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-non-human-identities/>)

Author: info@goteleport.com (Kayne McGladrey)

Published: 2026-06-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

This article explains how Teleport maps workload attestation, short-lived certificates, access rules, and audit logs for non-human identities to SOC 2 controls CC6, CC7, and CC8. It describes evidence auditors can use, including access rules, denied credential issuance logs, and Sigstore policy configurations where enabled.

### Source excerpt

Discover how to meet SOC 2 CC6, CC7, and CC8 controls for non-human identities.

## How to Eliminate Shared Database Passwords: MySQL, PostgreSQL, and More

DevFeed: [How to Eliminate Shared Database Passwords: MySQL, PostgreSQL, and More](<https://devfeed.tech/articles/how-to-eliminate-shared-database-passwords-mysql-postgresql-and-more-29634.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eliminate-shared-database-passwords/>)

Author: info@goteleport.com (Dan Johns)

Published: 2026-06-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Databases](<https://devfeed.tech/topics/databases.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [apply](<https://devfeed.tech/tags/apply.md>), [audit](<https://devfeed.tech/tags/audit.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [database](<https://devfeed.tech/tags/database.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [policy](<https://devfeed.tech/tags/policy.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

A guide to replacing shared database passwords and standing privileges with short-lived certificates and identity-based access. It explains how Teleport supports MySQL, PostgreSQL, and other databases, including role-based permissions, hardware-key approval for writes, and query-level attribution in audit logs.

### Source excerpt

Learn how to access MySQL, PostgreSQL, and other databases using short-lived certificates instead of shared passwords.

## How to Make Trading Infrastructure Audit-Ready Across SSH, Kubernetes, Databases, and RDP

DevFeed: [How to Make Trading Infrastructure Audit-Ready Across SSH, Kubernetes, Databases, and RDP](<https://devfeed.tech/articles/how-to-make-trading-infrastructure-audit-ready-across-ssh-kubernetes-databases-and-rdp-29573.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/audit-ready-trading-infrastructure/>)

Author: info@goteleport.com (Gus Luxton)

Published: 2026-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [audit](<https://devfeed.tech/topics/audit.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [rdp](<https://devfeed.tech/tags/rdp.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article explains how SSH, Kubernetes, databases, and RDP create audit challenges for high-frequency and quantitative trading firms. It describes the need for identity-attributed evidence and unified audit trails across protocols to support regulatory assessments.

### Source excerpt

Learn how SSH, Kubernetes, database, and RDP create audit challenges for high-frequency and quant trading firms and how to unify audit trails across protocols.

## What SPIFFE Answers for Workload Identity and What It Doesn't

DevFeed: [What SPIFFE Answers for Workload Identity and What It Doesn't](<https://devfeed.tech/articles/what-spiffe-answers-for-workload-identity-and-what-it-doesn-t-29859.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/spiffe-workload-identity/>)

Author: info@goteleport.com (Rob Cobbins)

Published: 2026-05-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [passwd](<https://devfeed.tech/topics/passwd.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [aws](<https://devfeed.tech/tags/aws.md>), [identity](<https://devfeed.tech/tags/identity.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [passwd](<https://devfeed.tech/tags/passwd.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [saml](<https://devfeed.tech/tags/saml.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>)

### AI overview

This article examines what SPIFFE provides for workload identity and where it falls short. It argues that SPIFFE offers a sound way for machines to prove their identities without shared secrets, but does not define authorization and leaves workload registration largely to implementations.

### Source excerpt

Learn about the workload identity questions SPIFFE can't answer and considerations for filling gaps in the spec.

[Next page](<https://devfeed.tech/sources/teleport.md?cursor=WyIyMDI2LTA1LTI5VDAwOjAwOjAwKzAwOjAwIiwgImFhNThiM2JjLTdmNzYtNDU4MC05ZjMzLWUzNTBhZTI3YWFiZiJd>)