Ansible and Terraform Still Need SSH Keys. That's a Problem You Can Fix
Blog post from Twingate
Infrastructure-as-code tools such as Ansible, Terraform, and Packer commonly rely on SSH to access hosts but leave credential management to operators, leading teams to use long-lived private keys on laptops, CI runners, or secrets managers. These distributed keys are difficult to inventory, rotate, revoke, and audit, while Vault-issued short-lived SSH certificates improve security but require substantial operational investment in infrastructure, policies, certificate authorities, and host configuration. The text presents Twingate Privileged Access and its Identity Firewall as an alternative that routes SSH traffic through an identity-aware Zero Trust layer, allowing users or CI service accounts to authenticate through an identity provider rather than storing SSH keys on runners. Twingate Connectors make outbound connections from target networks, potentially eliminating inbound SSH exposure and associating access logs with individual identities, although target hosts still require an operating-system-level authentication method. The proposed approach shifts trust to a Zero Trust access provider and aims to reduce credential distribution, rotation work, public management access, and the impact of compromised runners.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 18 | 2,244 | 480 | 132 | -13% |
| Platform Engineering | 13 | 1,191 | 259 | 79 | -17% |
| Zero Trust | 2 | 201 | 62 | 27 | -20% |
| Kubernetes | 1 | 3,490 | 385 | 112 | +26% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.