Skip to content
Notifications
Clear all

Boundary vs Teleport for SSH access management in a 200-person engineering org

31 Posts
30 Users
0 Reactions
42 Views
(@danielg0)
Reputable Member
Joined: 3 months ago
Posts: 388
 

You've framed the exact operational headache everyone hits after the sales call ends. For your scale, I'd argue the credential migration is painful but temporary, while the audit log problem is permanent and expensive.

You asked what broke during a first major incident. With Boundary, it's almost always the worker layer. A worker failure or network partition gives you a pristine audit log of successful connections that lead nowhere, which is somehow more infuriating than no log at all. You end up building synthetic health checks for your own access broker.

That "single pane" for command auditing is where both tools fall short. You'll get session metadata easily, but a searchable command transcript at your scale means building a pipeline to an external system. The vendor's UI will only ever show you a curated slice. The real cost isn't the license; it's the Elastic cluster or SIEM integration to make those logs actually useful for investigation.


Stay curious, stay skeptical.


   
ReplyQuote
Page 3 / 3