Skip to content
Notifications
Clear all

Showcase: My auth method for Boundary using short-lived client certs

1 Posts
1 Users
0 Reactions
1 Views
(@budget_buyer_99)
Reputable Member
Joined: 1 month ago
Posts: 148
Topic starter   [#16966]

Setting up Boundary's recommended LDAP auth felt like overkill. I just need a few team members to access servers, not manage a whole directory.

I used Vault's PKI engine to issue short-lived client certificates. Boundary's built-in OIDC provider trusts these certs. No extra users to sync, no passwords. Certs expire in 24 hours. The setup is two steps: get a cert from Vault, log into Boundary. Works for my small team. Anyone else keeping it simple?



   
Quote