Product · Beta

Warden

Warden gives engineers access to servers, Kubernetes, databases and Windows desktops through short-lived certificates issued after single sign-on, and records what they do. It replaces VPNs, shared SSH keys and static database passwords.

Who it is for

Platform and security teams that have outgrown shared keys and VPNs, and service providers that need access to many customer environments, each under the customer's control.

Works with

OpenID ConnectSAML 2.0Active DirectorySCIM 2.0KubernetesPostgreSQLOpenSSHS3-compatible storageSplunk and syslog

What it does

Short-lived certificates

After login, each session gets a certificate that expires by itself. There is nothing to rotate, and nothing left over when someone leaves.

One entry point

SSH with session recording, Kubernetes through an authenticating proxy, PostgreSQL with query auditing, Windows desktops over RDP and internal web applications, all behind the same login. Users sign in with OpenID Connect, SAML 2.0 or Active Directory, and SCIM provisions them.

Roles and temporary access

Roles are based on labels and can require MFA. People can ask for a role for a limited time, approved by someone else, and a lock cuts off a user or a machine immediately.

Audit log

The log is hash-chained and a command checks its integrity. SSH sessions are recorded and can be replayed in the console, and events can go to your SIEM.

No inbound ports

Agents next to your resources connect outward to Warden over mutual TLS, so protected networks do not need to open a single port.

How it works

  1. 01

    Sign in

    You log in with your company account. Warden issues a short-lived certificate and renews it in the background.

  2. 02

    Connect

    Each SSH, kubectl, database or desktop session asks for its own certificate. Roles, MFA and locks are checked at that moment, the request is logged, and an agent next to the resource routes and records the session.

  3. 03

    Review

    To find out who did what, verify the audit chain, replay the recording or look in your SIEM.

Shared SSH keys, VPNs and database passwords that nobody rotates make it hard to say who can reach what, and every departure turns into a checklist. Warden uses your company login instead: each session gets a short-lived certificate for exactly what the person may reach.

Service providers can manage many customer clusters from one place, with each customer deciding what flows upward. Warden is self-hosted: one binary and one container image, installed with a Helm chart on Kubernetes or with Docker Compose on a plain VM, with apps for macOS and Windows.

We built it for our own work, since we reach customers’ clusters, servers and databases every day, and it runs on our own infrastructure today.

Warden is in beta

See Warden with your own setup in mind.

Tell us what you run today and we will show you what it does. Pricing and licensing are discussed with each company.

Request a demo