But as often is the case, a shift to something new is first gradual until it gains momentum.
We at SSH launched our container support for our Zero Trust and just-in-time (JIT) privileged access management (PAM) solution PrivX two years ago at RSA. Since then, we have been developing the technology further together with our key customers.
Now, the first Kubernetes implementations are being deployed in customer environments, and we announced our first “container-first” privileged access management (PAM) deal just recently Companies at the cutting edge of technology are serious about securing their Kubernetes-orchestrated environments. Learn more about why a Fortune 500 company decided to implement our container-friendly PAM solution to secure their SSH connections to container environments. PrivX 20 and secure Kubernetes orchestration Building a solution that not only solves the problems that exist today but is also future-proof takes some first-mover courage. And now, there’s growing interest for solutions that allow customers to not only solve their current privileged access management (PAM) challenges, but migrate from legacy to the future at their own pace.
Companies who are already running their applications and services in containers orchestrated by Kubernetes, or are planning to make the move in the future, can really benefit from the new deployment model of PrivX.
Running PrivX on Kubernetes takes full advantage of the PAM solution’s modern microservices architecture. Case in point: service-specific scalability can be done based on the load. For example, if there is a sudden spike in the number of concurrent SSH sessions needed, you only need to scale up the PrivX SSH proxies, instead of entire instances. The same logic applies to all other PrivX microservices.
Since PrivX saves resources by scaling up only the services needed at a particular time, it has a direct link to reducing costs. In an environment with thousands of users and thousands of dynamic hosts, these resource and cost savings are significant. No need to buy extra hardware or processing power to secure your environment. Instead, you can optimize the use of existing resources to the maximum with a containerized approach while still maintaining the required redudancy levels.
On-prem, cloud or hybrid: choose your deployment Auto-scaling of PrivX instances has been available for cloud deployments (AWS, Azure, GCP) for a while, but with PrivX 20, this feature is now possible on your own hardware. The result is that high availability (HA) environments are easier to setup. With PrivX 20 you can run your container estate in the cloud, on-premises or as hybrid, since you still get the same level of performance and automation in both worlds.
Some generic benefits of running applications and services on Kubernetes apply to PrivX: Easy maintenance Monitoring and access management on the Kubernetes level Security isolation, immutabilty (learn more about access management and immutable infrastructure here) Self-healing environments and resiliency Running PrivX in container environments takes the already future proof solution to the next level. Since we don’t live in an ideal world, we understand that the customer environments host technologies at various stages of maturity. That is why the array of supported technologies in PrivX range all the way from legacy on-prem installations to cloud services to modern containers. Passwordless, keyless and just-in-time access aligning with Zero Trust PrivX builds you a path to passwordless, just-in-time (JIT) and Zero Trust access. Simply put it means that your privileged users never handle or see any secrets when establishing a connection. In fact, the connection is made using short-lived, ephemeral certificates that are created just-in time at the time of the connection. They contain all the secrets needed for the session (like passwords), but after the connection is made, the certificates expire automatically. This means that there are no credentials, passwords, keys or secrets to manage, lose or misuse! Furthermore, this approach radically reduces the overhead of managing secrets, since there are less of them to manage. With thousands of users and thousands of dynamic servers, the reduction in processing power is radical. Since a new session is verified in a similar fashion every time, PrivX aligns perfectly with Zero Trust, since no one has permanent access to the environment. Environments very in their technological maturity level. This is why PrivX comes equipped with a secrets vaultfor those contexts where passwordless authentication is not possible but you still need to vault secrets. PrivX simply is your trusted and centralized gatekeeper to manage access to legacy and future-driven apps. OIDC login support for native SSH clients We highly recommend using browsers to make SSH connections, but in some cases there is a need to use native clients. That is why the support for native clients has been in PrivX for years. In PrivX 11 we introduced the feature to use the bastion syntax for making SSH connections through PrivX. PrivX 18 made it possible to use native clients without a need to make any changes to existing commands or scripts (no need to use bastion syntax).
Now we bring the Open ID Connect (OIDC) to the fold. With PrivX 20, it is possible to do a browser based OIDC login and then use authorized keys to log in to the SSH-bastion. Zero Trust PrivX Key Manager and PrivX - better together You might have noticed that we have aligned our entire solution portfolio with the Zero Trust and Just-in-Time frameworks. In release 20, it is possible to launch our enterprise key management solution - Universal SSH Key Manager- directly from the PrivX UI.
Our classic PrivX Key Manager solution allows customers to take control of their large SSH key estates by discovering rogue keys and providing a complete view of how their keys are used. Customers can identify policy or compliance violating keys, find those that grant access from test to production or are still used by that 3rd party consultant who left the project two years ago – and then remedy the situation. This solution is largely used by heavily-regulated and audited Fortune 500 companies with large, legacy key estates. Zero Trust key management with just-in-time access Our PrivX Key Manager Zero Trust solutionnot only allows customers to manage keys, but significantly reduce the number of keys they need to manage in the first place. In this model, an SSH connection is no longer established using keys but with ephemeral certificates that are created just-in-time (JIT)and that contain the key secrets needed for the connection. If this sounds familiar, it's because I explained it just a few sections before! So why to bring certificate-based authentication to key management? Think about the reduction in the management overhead in key estates that encompass tens or hundreds of thousands of keys and servers. With Fortune 500 companies, this is often the case. Even with the best solution on the market, we are talking about rotating thousands of keys per day! When you gradually start moving to ephemeral access, you simply decrease the size and complexity of the risk you are trying to manage in the first place. It really boils down to the question: would you rather manage thousands of secrets by using more and more resources or manage less without the need to add resources?
With the combined Just-in-Time Zero Trust solution of PrivX Key Manager and PrivX, you have a lot of bases covered: you manage, secure and vault those secrets (keys, API tokens, passwords, etc) that you still have to while you gradually start to migrate to a keyless and passwordless world. That's where the futureis heading anyway.
PS. The PrivX project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 881221. Tag(s): Privileged Access Management , PrivX Esa Tornikoski Esa Tornikoski is Product Manager for PrivX and Crypto Auditor products. Esa joined SSH late 2017. Prior SSH he has been working in Product management roles at Telecom and IT security companies (Elisa, F-Secure and Siemens). He has a Master of Science degree in Computer Science from Lappeenranta University of... Other posts you might be interested in Privileged Access Management 10 min read | May 17, 2024 Overcoming Implementation Challenges in Privileged Access Management: A Step-by-Step Guide Read More Zero Trust 12 min read | January 9, 2020 Cool PAM with great auditing and easy access to IT assets in the cloud Read More Privileged Access Management 13 min read | May 17, 2024 How to do a Privileged Access Management Audit? Read More Subscribe to email updates SSH is a leading defensive cybersecurity company that secures communications between humans, systems, and networks. We specialize in Zero Trust Privileged Access Controls and Quantum Safe Network Security. Our customers include a diverse range of enterprises, from multiple Fortune 500 companies to SMBs across various sectors such as Finance, Retail, Technology, Industrial, Healthcare, and Government. 25% of Fortune 100 companies rely on SSH’s solutions. Recent strategic focus has expanded SSH business to Defence, Critical Infrastructure Operators, Manufacturing OT Security and Public Safety. Leonardo S.p.A invests 20.0 million EUR in SSH, becoming the largest shareholder of the company. SSH solutions form a Center of Excellence for Zero Trust privileged access management and quantum-safe network encryption in Leonardo - a global industrial group that creates multi-domain technological capabilities in the Aerospace, Defence and Security sector with 17.8 billion EUR revenue in 2024. SSH company’s shares (SSH1V) are listed on Nasdaq Helsinki. Solutions Zero Trust Suite Zero Trust Suite & Entra ID Integration Quantum-Safe Cryptography (QSC) SalaX Secure Collaboration Security Risk Mitigation OT security MSP Security Device Trust Monitoring & Threat Intelligence Credentials & Secrets Management IT Audits & Compliance Products PrivX™ Hybrid PAM PrivX Key Manager Tectia SSH Client/Server™ Tectia™ z/OS Secure Messaging Secure Mail Secure Sign NQX™ Quantum-Safe Services SSH Risk Assessment™ Professional Services Support Resources Careers References Downloads Manuals Events & Webinars Blog Company About us Contact Investors Partners Press Stay on top of the latest in cybersecurity Be the first to know about SSH’s new solutions, product updates, new features, and other SSH news! Thanks for submitting the form. © Copyright SSH • 2025 • Legal
智能索引记录
-
2026-02-27 01:34:01
综合
成功
标题:Kentucky Equine Research - World Leaders In Equine Research & Nutrition
简介:Kentucky Equine Research (KER) is an international equine nu
-
2026-02-27 02:12:26
综合
成功
标题:Hengki Lee
简介:1x.com is the world
-
2026-02-27 01:35:20
教育
成功
标题:关于一年级作文合集七篇
简介:在生活、工作和学习中,大家都经常接触到作文吧,写作文可以锻炼我们的独处习惯,让自己的心静下来,思考自己未来的方向。那么你
-
2026-02-27 01:59:18
综合
成功
标题:La Bible des contrastes – Méditations par la plume et le trait – Excelsis
简介:Ce bel ouvrage rassemble plus de quarante années de méditati
-
2026-02-27 02:15:40
商城
成功
标题:京东(JD.COM)-正品低价、品质保障、配送及时、轻松购物!
简介:京东JD.COM-专业的综合网上购物商城,为您提供正品低价的购物选择、优质便捷的服务体验。商品来自全球数十万品牌商家,囊
-
2026-02-27 01:15:09
综合
成功
标题:Logistics Real Estate GLP Europe
简介:GLP Europe is a logistics real estate developer and operator
-
2026-02-26 23:55:56
综合
成功
标题:Market Strategy NDR Investment Research
简介:Market insights, select indicators and reports covering econ
-
2026-02-26 23:43:28
综合
成功
标题:Crosser2. World English Historical Dictionary
简介:Crosser2. World English Historical Dictionary
-
2026-02-27 01:49:18
综合
成功
标题:Brennstoffzellen - JW Froehlich Maschinenfabrik GmbH
简介:Brennstoffzelle - Technologisches Leadership und langjährige
-
2026-02-27 01:51:23
综合
成功
标题:Nuevo Audi RS 5: 639 CV y 2445 kg. El dilema del peso - Revista km77
简介:El nuevo Audi RS 5 Avant 2026 pesa 625 kg más que el RS 4 Av
-
2026-02-27 00:00:57
综合
成功
标题:EA-PUL 10000 4U - Programmable Electronic DC Loads with energy recovery Tektronix
简介:EA-PUL 10000 4U
-
2026-02-26 23:49:19
综合
成功
标题:Fish Attorneys Author Law360 Article on Contingent Fees
简介:Fish attorneys Tommy Jacks and David Hoffman authored
-
2026-02-27 02:23:58
综合
成功
标题:MatchersBuiltin.toBeBoolean method bun:test module Bun
简介:API documentation for method bun:test.MatchersBuiltin.toBeBo
-
2026-02-27 02:04:47
综合
成功
标题:运力紧张推升油轮运费,聚焦石化ETF(159731)格局优化及高质量发展 etf 化工品 原油 地缘风险 油价 油轮 运费_手机网易网
简介:截至2月26日14点31分,石化ETF(159731)涨0.75%,持仓股盐湖股份、蓝晓科技、藏格矿业等涨幅居前。从资金
-
2026-02-27 00:13:53
综合
成功
标题:1960's Paul Reevs Sequin Micro Mini Dress Mou Official Website
简介:Paul Reeves for the Universal Witness sequin Micro Mini Dres
-
2026-02-27 01:30:54
综合
成功
标题:Fisher Investments Wealth Management
简介:Founded in 1979, Fisher Investments is an independent regist
-
2026-02-27 02:07:02
视频
成功
标题:拐个原始人当老公第15集河马短剧_在线播放[高清流畅]_爽文短剧
简介:爽文短剧_拐个原始人当老公剧情介绍:拐个原始人当老公是由内详执导,内详等人主演的,于2025年上映,该都市讲述的是@电@
-
2026-02-27 01:26:06
综合
成功
标题:2020广东注册安全工程师报名入口8月18日开通,进入报名-中级注册安全工程师-233网校
简介:2020广东注册安全工程师报名入口8月18日开通,8月27日截止报名。报考人员可登录中国人事考试网(link.233.c
-
2026-02-27 00:30:18
综合
成功
标题:上海初中数学课后补习班-上海初中数学辅导老师-新王牌培优
简介:硕士工科毕业,教学经验丰富,因课堂高互动及对学生的高度关注,被学生称赞“互动能手”。
-
2026-02-26 23:52:05
综合
成功
标题:Book Printing PIP - PIP Indianapolis, IN
简介:Let PIP build your classic with bookbindery, printing, and v
-
2026-02-27 00:49:40
游戏
成功
标题:造梦无双狐狸和兔子哪个更强 宠物技能对比_欢乐园游戏
简介:造梦无双里狐狸和兔子都是充钱才可以得到的宠物,其中狐狸是VIP5专属的,而兔子是中秋活动宠物,现在已经绝版,那么狐狸和兔
-
2026-02-27 01:23:45
综合
成功
标题:Jorge Eliecer Moreno
简介:Jorge Eliecer Moreno
-
2026-02-27 02:26:45
综合
成功
标题:Retailer integration (ship-from-store)
简介:The integration of local retail into the e-commerce strategy
-
2026-02-27 01:11:32
综合
成功
标题:旺夫女属相揭秘:谁最旺夫?_一世迷命理网
简介:生肖文化深入人心,人们常常通过生肖来判断一个人的性格、命运和运势。关于旺夫运的说法更是备受关注。哪些属相生肖的女人被认为
-
2026-02-27 00:53:15
综合
成功
标题:État de votre commande - Aide à l’achat - Éducation - Apple (CH)
简介:État de votre commande
-
2026-02-27 00:28:51
综合
成功
标题:Seattle Kraken Club Stats 2025 - 2026 Seattle Kraken
简介:Stats for the Seattle Kraken in the 2025 - 2026 season.
-
2026-02-27 01:16:25
图片
成功
标题:旧建筑改建景观餐厅拆除原建筑立面仅__别墅设计图
简介:居住成员:装潢费用:-房屋平数:150平设计风格:奢华风格房屋类型:民宿旅馆房屋状况:图片提供:YHS设计事业空间格局:
-
2026-02-27 00:06:39
工具
成功
标题:临时老公,太傲骄!_一千万_第103章:强押着她结婚!_风云中文网
简介:风云中文网提供临时老公,太傲骄!(一千万)第103章:强押着她结婚!在线阅读,所有小说均免费阅读,努力打造最干净的阅读环
-
2026-02-27 00:31:45
综合
成功
标题:龙宫的拼音_龙宫的意思_龙宫的繁体_词组网
简介:词组网龙宫频道,介绍龙宫,龙宫的拼音,龙宫是什么意思,龙宫的意思,龙宫的繁体,龙宫怎么读,龙宫的近义词,龙宫的反义词。
-
2026-02-27 01:10:51
综合
成功
标题:Thomas of Woodstock, Duke of Gloucester (1355-1397). The Reader's Biographical Encyclopaedia. 1922
简介:Thomas of Woodstock, Duke of Gloucester (1355-1397). The Rea