Managing infrastructure access for distributed engineering teams across Karachi, Lahore, and Islamabad using traditional static SSH keys and shared database passwords presents significant operational risk:
- SSH Key Proliferation: Public SSH keys remain in
~/.ssh/authorized_keyslong after contractors, agencies, or junior developers leave the company. - Zero Session Observability: Standard OpenSSH logging records only when a user logs in, with no record of commands executed or files exfiltrated.
- Exposed Administrative Ports: Exposing SSH port 22 or database port 5432 directly to the public internet invites automated brute-force attacks and port scanning.
Teleport (by Gravitational) is an open-source, identity-aware Zero-Trust Access Gateway that eliminates static credentials. Teleport replaces long-lived SSH keys with short-lived, cryptographically signed X.509 and OpenSSH certificates issued via Single Sign-On (SSO). It provides centralized access, role-based access control (RBAC), and video-like session recording for SSH, Kubernetes, web applications, and database connections.
This guide provides a comprehensive production deployment and tuning blueprint for hosting Teleport Community Edition on Linux VPS and bare metal infrastructure in Pakistan.
1. Zero-Trust Access Architecture
Teleport acts as a secure reverse-proxy bastion between engineers and internal servers:
Remote Engineers & DBAs (Workstations across Pakistan)
│
▼ (HTTPS / Port 443 with WebAuthn 2FA)
[Teleport Auth & Proxy Gateway (Port 443)]
- Authenticates users via SSO / WebAuthn
- Issues 8-hour OpenSSH & TLS Certificates
- Enforces Role-Based Access Control (RBAC)
- Records full interactive terminal sessions
│
┌────────────────┼────────────────┐
▼ (mTLS Reverse ▼ (Database Wire ▼ (Kubernetes API)
Tunnel) Protocol)
┌────────────────┐ ┌────────────────┐ ┌────────────────┐
│ Production SSH │ │ MariaDB / Post-│ │ K8s Worker Node│
│ (Zero Open Port│ │ greSQL Cluster │ │ (Audit Monit- │
│ to Internet!) │ │ (Short-lived DB│ │ ored Access) │
└────────────────┘ └────────────────┘ └────────────────┘
Key Security Benefits:
- Zero Open Ports on Production Nodes: Target servers connect outbound to the Teleport proxy over an encrypted reverse tunnel. SSH port 22 is completely closed to the internet.
- Deterministic Audit Compliance: Every shell keystroke, database query, and terminal session is recorded and searchable, satisfying SECP and State Bank of Pakistan compliance requirements.
- Cryptographic Expiration: User access certificates expire automatically (e.g., after 8 hours), eliminating the risk of lost developer laptops or compromised credentials.
For organizations running multi-tenant container fleets or fintech backends that must adhere to SECP and State Bank of Pakistan cybersecurity compliance standards, deploying on Dedicated Servers in Pakistan provides physical hardware separation, dedicated storage arrays, and complete operational autonomy.
2. Installing Teleport Community Edition on Ubuntu
Install Teleport on your gateway host:
# Add official Teleport GPG key and repo
sudo curl https://apt.releases.teleport.dev/gpg \
-o /usr/share/keyrings/teleport-archive-keyring.asc
echo "deb [signed-by=/usr/share/keyrings/teleport-archive-keyring.asc] https://apt.releases.teleport.dev/ubuntu jammy stable/v15" \
| sudo tee /etc/apt/sources.list.d/teleport.list
sudo apt-get update
sudo apt-get install -y teleport
3. Configuring Teleport Gateway (/etc/teleport.yaml)
Edit /etc/teleport.yaml:
version: v3
teleport:
nodename: teleport-gateway-pk
data_dir: /var/lib/teleport
log:
output: stderr
severity: INFO
format:
output: text
auth_service:
enabled: yes
listen_addr: 0.0.0.0:3025
cluster_name: enterprise.teleport.internal
authentication:
type: local
second_factor: on # Enforces WebAuthn / TOTP for all engineers
ssh_service:
enabled: yes
listen_addr: 0.0.0.0:3022
proxy_service:
enabled: yes
# Multiplex all traffic cleanly over standard HTTPS port 443
web_listen_addr: 0.0.0.0:443
public_addr: teleport.enterprise.pk:443
acme:
enabled: yes
email: [email protected]
Enable and start the Teleport daemon:
sudo systemctl enable --now teleport
4. Creating Administrative Users and 2FA Enrollment
Create your initial administrative user:
sudo tctl users add farhan --roles=editor,access --logins=root,ubuntu,farhan
The CLI outputs an enrollment URL:
https://teleport.enterprise.pk:443/web/invite/948201840192840...
Open the link in your browser to scan a TOTP QR code (or tap a physical YubiKey/WebAuthn key) and set a secure passphrase.
5. Connecting Target Nodes via Reverse Tunnels
On target production servers (e.g., application and database nodes), generate a join token from the Teleport gateway:
sudo tctl tokens add --type=node
On the target node, install Teleport and join via the reverse tunnel:
sudo teleport node configure \
--token="YOUR_JOIN_TOKEN" \
--proxy="teleport.enterprise.pk:443" \
--nodename="app-worker-01" | sudo tee /etc/teleport.yaml
sudo systemctl enable --now teleport
The target node opens an outbound TLS tunnel to the Teleport gateway. Port 22 remains closed on the host firewall.
6. Accessing Servers via tsh CLI
Developers and administrators access production infrastructure using the tsh tool:
# Authenticate and receive short-lived 8-hour certificate
tsh login --proxy=teleport.enterprise.pk:443 --user=farhan
# List active infrastructure nodes
tsh ls
# Connect securely with session recording active
tsh ssh root@app-worker-01
All commands executed during the session are cryptographically signed, recorded, and viewable in the Teleport web dashboard for security audit reviews.
7. Architectural Comparison: Access Solutions
| Feature | Direct OpenSSH with Keys | Bastion Host (Jump Box) | Teleport Zero-Trust Gateway |
|---|---|---|---|
| Credential Type | Permanent static SSH keys | Permanent static SSH keys | Short-Lived Ephemeral Certs (8h) |
| Open Inbound Ports | Port 22 open to internet | Port 22 open to internet | Zero Inbound Ports (Reverse Tunnel) |
| Multi-Factor Auth (MFA) | Complex PAM modules | Limited | Native Hardware WebAuthn / FIDO2 |
| Audit Session Replay | None (Basic text logs) | Ttyrec (Clunky) | Full Video Keystroke Playback |
| Database & K8s Access | Open VPN tunnels required | Open VPN tunnels required | Native Identity-Aware Proxying |
For organizations seeking high availability without the overhead of physical hardware management, our high-spec Cloud VPS instances provide private virtual networking and sub-15ms domestic ping times across Pakistan.
When deploying mission-critical enterprise clusters across multinational data centers, combining local failover pairs with global Dedicated Servers provides redundant transit lines and carrier-neutral Tier-1 peering.
Related Security & Infrastructure Guides
Further expand your DevOps and server architecture knowledge:
- Enterprise Drupal Hosting Architecture and Production Tuning
- MariaDB and MySQL Performance Tuning on Linux VPS
- WAF Firewall Bypass Audit and OWASP Top 10 Hardening
Eliminate Static SSH Keys on NextGen Infrastructure
Protect your production fleet with certificate-based zero-trust access. Deploy Teleport on high-performance Linux VPS with pure NVMe storage arrays, local PKIX peering, and 24/7 dedicated engineering support in Pakistan.
