Skip to content
Notifications
Clear all

Boundary vs. Teleport for internal admin access - real numbers?

1 Posts
1 Users
0 Reactions
3 Views
(@brianl)
Estimable Member
Joined: 1 week ago
Posts: 113
Topic starter   [#7773]

I've been researching solutions for securing internal administrative access to our on-premises and cloud infrastructure, and the shortlist has come down to HashiCorp Boundary and Teleport. I work in an environment with a mix of legacy manufacturing systems, modern ERP instances like NetSuite, and various databases, so the need for a robust access control layer is critical. While I've read the official documentation and marketing materials for both, I'm finding it difficult to locate concrete, real-world operational metrics and comparative data from production implementations.

My primary interest lies in understanding the tangible differences that impact day-to-day operations and total cost of ownership. For instance, I am curious about the actual session latency introduced by each solution when connecting to a PostgreSQL database or a Windows server hosting a legacy application. Are we talking about milliseconds of overhead, or something more noticeable that could affect administrative workflows? Furthermore, the architectural model of Boundary, with its need for worker nodes, seems to have different infrastructure implications compared to Teleport's agent-based approach. I would be very interested to hear from teams who have deployed either at scale regarding the resource consumption and management overhead of these components.

Another area where I struggle to find clear numbers is around scaling and licensing costs for larger teams. Both offer enterprise versions, but the pricing models seem to diverge significantly. For those managing several hundred administrators and thousands of target servers, how does the cost structure compare when you factor in required nodes, support contracts, and any necessary integrations? In the context of ERP and supply chain systems, where access often needs to be tightly coupled with change management tickets, I'm also keen to learn about the practical ease of integrating either tool with IT Service Management platforms. Which one required less custom development to achieve a seamless, auditable workflow?

Finally, from a security posture perspective, I've read the feature lists about credential brokering and session recording. However, I'm looking for practical feedback on the implementation and maintenance of these features. How reliable is the session recording playback, and what is the storage impact for organizations that maintain logs for compliance purposes? Has anyone performed a detailed comparison of the credential injection mechanisms for database access, particularly with systems like SAP HANA or Oracle E-Business Suite? Any insights, especially those backed by operational data or detailed deployment stories, would be immensely valuable as we move towards a final selection.



   
Quote