Teleport Zero-Trust Access Gateway: Eliminating Static SSH Keys and VPNs on Linux in Pakistan

A production guide to deploying Gravitational Teleport Access Gateway on Linux VPS in Pakistan. Secure SSH, Kubernetes, and database access using certificate-based authentication, SSO, and audit session recording.

Teleport Zero-Trust Access Gateway: Eliminating Static SSH Keys and VPNs on Linux in Pakistan

Managing infrastructure access for distributed engineering teams across Karachi, Lahore, and Islamabad using traditional static SSH keys and shared database passwords presents significant operational risk:

  1. SSH Key Proliferation: Public SSH keys remain in ~/.ssh/authorized_keys long after contractors, agencies, or junior developers leave the company.
  2. Zero Session Observability: Standard OpenSSH logging records only when a user logs in, with no record of commands executed or files exfiltrated.
  3. Exposed Administrative Ports: Exposing SSH port 22 or database port 5432 directly to the public internet invites automated brute-force attacks and port scanning.

Teleport (by Gravitational) is an open-source, identity-aware Zero-Trust Access Gateway that eliminates static credentials. Teleport replaces long-lived SSH keys with short-lived, cryptographically signed X.509 and OpenSSH certificates issued via Single Sign-On (SSO). It provides centralized access, role-based access control (RBAC), and video-like session recording for SSH, Kubernetes, web applications, and database connections.

This guide provides a comprehensive production deployment and tuning blueprint for hosting Teleport Community Edition on Linux VPS and bare metal infrastructure in Pakistan.


1. Zero-Trust Access Architecture

Teleport acts as a secure reverse-proxy bastion between engineers and internal servers:

Remote Engineers & DBAs (Workstations across Pakistan)
                         │
                         ▼ (HTTPS / Port 443 with WebAuthn 2FA)
             [Teleport Auth & Proxy Gateway (Port 443)]
             - Authenticates users via SSO / WebAuthn
             - Issues 8-hour OpenSSH & TLS Certificates
             - Enforces Role-Based Access Control (RBAC)
             - Records full interactive terminal sessions
                         │
        ┌────────────────┼────────────────┐
        ▼ (mTLS Reverse  ▼ (Database Wire  ▼ (Kubernetes API)
           Tunnel)          Protocol)
 ┌────────────────┐ ┌────────────────┐ ┌────────────────┐
 │ Production SSH │ │ MariaDB / Post-│ │ K8s Worker Node│
 │ (Zero Open Port│ │ greSQL Cluster │ │ (Audit Monit- │
 │  to Internet!) │ │ (Short-lived DB│ │  ored Access)  │
 └────────────────┘ └────────────────┘ └────────────────┘

Key Security Benefits:

  1. Zero Open Ports on Production Nodes: Target servers connect outbound to the Teleport proxy over an encrypted reverse tunnel. SSH port 22 is completely closed to the internet.
  2. Deterministic Audit Compliance: Every shell keystroke, database query, and terminal session is recorded and searchable, satisfying SECP and State Bank of Pakistan compliance requirements.
  3. Cryptographic Expiration: User access certificates expire automatically (e.g., after 8 hours), eliminating the risk of lost developer laptops or compromised credentials.

For organizations running multi-tenant container fleets or fintech backends that must adhere to SECP and State Bank of Pakistan cybersecurity compliance standards, deploying on Dedicated Servers in Pakistan provides physical hardware separation, dedicated storage arrays, and complete operational autonomy.


2. Installing Teleport Community Edition on Ubuntu

Install Teleport on your gateway host:

# Add official Teleport GPG key and repo
sudo curl https://apt.releases.teleport.dev/gpg \
  -o /usr/share/keyrings/teleport-archive-keyring.asc
echo "deb [signed-by=/usr/share/keyrings/teleport-archive-keyring.asc] https://apt.releases.teleport.dev/ubuntu jammy stable/v15" \
  | sudo tee /etc/apt/sources.list.d/teleport.list

sudo apt-get update
sudo apt-get install -y teleport

3. Configuring Teleport Gateway (/etc/teleport.yaml)

Edit /etc/teleport.yaml:

version: v3
teleport:
  nodename: teleport-gateway-pk
  data_dir: /var/lib/teleport
  log:
    output: stderr
    severity: INFO
    format:
      output: text

auth_service:
  enabled: yes
  listen_addr: 0.0.0.0:3025
  cluster_name: enterprise.teleport.internal
  authentication:
    type: local
    second_factor: on # Enforces WebAuthn / TOTP for all engineers

ssh_service:
  enabled: yes
  listen_addr: 0.0.0.0:3022

proxy_service:
  enabled: yes
  # Multiplex all traffic cleanly over standard HTTPS port 443
  web_listen_addr: 0.0.0.0:443
  public_addr: teleport.enterprise.pk:443
  acme:
    enabled: yes
    email: [email protected]

Enable and start the Teleport daemon:

sudo systemctl enable --now teleport

4. Creating Administrative Users and 2FA Enrollment

Create your initial administrative user:

sudo tctl users add farhan --roles=editor,access --logins=root,ubuntu,farhan

The CLI outputs an enrollment URL:
https://teleport.enterprise.pk:443/web/invite/948201840192840...

Open the link in your browser to scan a TOTP QR code (or tap a physical YubiKey/WebAuthn key) and set a secure passphrase.


5. Connecting Target Nodes via Reverse Tunnels

On target production servers (e.g., application and database nodes), generate a join token from the Teleport gateway:

sudo tctl tokens add --type=node

On the target node, install Teleport and join via the reverse tunnel:

sudo teleport node configure \
  --token="YOUR_JOIN_TOKEN" \
  --proxy="teleport.enterprise.pk:443" \
  --nodename="app-worker-01" | sudo tee /etc/teleport.yaml

sudo systemctl enable --now teleport

The target node opens an outbound TLS tunnel to the Teleport gateway. Port 22 remains closed on the host firewall.


6. Accessing Servers via tsh CLI

Developers and administrators access production infrastructure using the tsh tool:

# Authenticate and receive short-lived 8-hour certificate
tsh login --proxy=teleport.enterprise.pk:443 --user=farhan

# List active infrastructure nodes
tsh ls

# Connect securely with session recording active
tsh ssh root@app-worker-01

All commands executed during the session are cryptographically signed, recorded, and viewable in the Teleport web dashboard for security audit reviews.


7. Architectural Comparison: Access Solutions

Feature Direct OpenSSH with Keys Bastion Host (Jump Box) Teleport Zero-Trust Gateway
Credential Type Permanent static SSH keys Permanent static SSH keys Short-Lived Ephemeral Certs (8h)
Open Inbound Ports Port 22 open to internet Port 22 open to internet Zero Inbound Ports (Reverse Tunnel)
Multi-Factor Auth (MFA) Complex PAM modules Limited Native Hardware WebAuthn / FIDO2
Audit Session Replay None (Basic text logs) Ttyrec (Clunky) Full Video Keystroke Playback
Database & K8s Access Open VPN tunnels required Open VPN tunnels required Native Identity-Aware Proxying

For organizations seeking high availability without the overhead of physical hardware management, our high-spec Cloud VPS instances provide private virtual networking and sub-15ms domestic ping times across Pakistan.

When deploying mission-critical enterprise clusters across multinational data centers, combining local failover pairs with global Dedicated Servers provides redundant transit lines and carrier-neutral Tier-1 peering.


Further expand your DevOps and server architecture knowledge:

ZERO-TRUST INFRASTRUCTURE ACCESS

Eliminate Static SSH Keys on NextGen Infrastructure

Protect your production fleet with certificate-based zero-trust access. Deploy Teleport on high-performance Linux VPS with pure NVMe storage arrays, local PKIX peering, and 24/7 dedicated engineering support in Pakistan.