Hacker News new | ask | show | jobs
by apothegm 36 days ago
All production access should require SSHing through an instance in your VPC, enforced by a firewall. Remove access to hosting provider accounts; remove user account on that stepping stone instance. Voila, production access to infrastructure is eliminated.