Show HN: Cardea, SSH bastion with per-key ACLs, TPM keys and session recording

Show HN: Cardea, SSH bastion with per-key ACLs, TPM keys and session recording

Author here. Cardea is an SSH bastion I wrote to manage access to some servers I administer. Access policies are defined in a single text file, similar to OpenSSH's authorized_keys format, with macros, server groups, time windows, and key expiry, so everythin…

Cardea is an SSH bastion server with access control, session recording, and optional TPM-backed key protection. Cardea is designed for small and mid-sized teams that manage infrastructure through co… [+17610 chars]