The Secure Way
Identity and access, the secure way
Self-hosted identity with Zitadel, private access with Headscale, break-glass and offboarding.
9 guides
- A userspace Tailscale subnet router on Kubernetes, the secure wayRun a Tailscale subnet router in Kubernetes as non-root with no capabilities, an exact auto-approved route, per-service grants and a Role for its own state.
- Admin tools reachable only on a tailnet, the secure wayBind admin tools to loopback, publish them with tailscale serve, and grant one group one port. Tested end to end: ops gets in, dev and the LAN are refused.
- An insider kill switch, the secure wayCut a person out of OpenBao and the tailnet in seconds: disable the entity so every token dies, expire their devices, and verify. Deleting the login is not enough.
- Break-glass accounts, the secure wayDesign break-glass access that needs two parties, lives offline, alerts on use and is revoked after, shown end to end with OpenBao recovery shares and audit logs.
- Developer onboarding and offboarding, the secure wayGrant developer access through groups and single-use keys, and remove it with an inventory, expired devices and deleted accounts. Tested with Headscale.
- Forcing MFA in Zitadel, the secure wayForce MFA in Zitadel for every user, including those from external IdPs, and catch organizations that quietly override it. Real API output from Zitadel v4.
- Headscale with OIDC and deny-by-default ACLs, the secure wayRun Headscale with OIDC restricted to your domain and group, PKCE, expiring nodes, and a deny-by-default policy whose tests fail any change that opens more.
- Staff and customers in separate Zitadel organizations, the secure wayKeep Zitadel instance administrators in their own organization, away from customer orgs whose admins can reset their passwords. Real API output from Zitadel v4.
- Zitadel on Kubernetes, the secure wayDeploy Zitadel with Helm without the default admin password, a masterkey in values, plaintext to the pod or a 2029 admin key in a Secret. Tested and validated.
T Academy
Every guide here is taught hands-on in H2-CIAE Identity and Access Engineering: a real host in your browser, and every objective checked on the machine.
Start free