Fearless SSH: short-lived certificates bring Zero Trust to infrastructure
ID: f5cb782b-8d5d-5be5-a5aa-7077746af6d9
STIX ID: report--f5cb782b-8d5d-5be5-a5aa-7077746af6d9
Feed Name: Cloudflare Blog
Cloudflare announces Access for Infrastructure, a native integration of BastionZero into Cloudflare One, starting with short-lived SSH access that replaces passwords/keys with certificates issued by a Cloudflare-managed SSH CA. The service enforces Zero Trust policies (SSO, MFA, device posture), enables fine-grained authorization down to Linux users via certificate principals, and provides encrypted SSH command logs, all without changing end-user SSH workflows. An SSH proxy architecture mediates connections, preserves TOFU behavior, and leverages WARP and Cloudflare Tunnel, offering centralized policy, auditing, and simplified key management; it’s available now with free access for teams under 50 users and included for existing plans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
