Teleport is a zero-trust access platform that provides identity-based access to infrastructure resources such as Linux servers, Kubernetes clusters, databases, and applications. Teleport uses authentication and authorization controls to determine both the identity of a connecting entity and the resources that entity is permitted to access.
Teleport Machine & Workload Identity provides identity-based authentication for non-human identities such as automation services, CI/CD workloads, and other machine processes. Teleport uses short-lived certificates for these identities rather than relying on long-lived static credentials.
In this use case, a controlled Teleport Zero Trust access infrastructure is deployed on Ubuntu Linux inside an isolated VirtualBox laboratory. A second Ubuntu or Linux target server is enrolled into the Teleport cluster as the protected infrastructure resource. Kali Linux is used as the authorized security-testing environment.
A controlled service identity is created to represent a laboratory automation workload. The service identity is assigned a narrowly scoped Teleport role that permits access only to a designated laboratory resource identified through Teleport resource labels.
The security assessment attempts to bypass this policy by using the valid service identity to request or establish access to a resource outside the identity's permitted scope. The assessment does not attempt to forge Teleport certificates or compromise the Teleport Certificate Authority. Instead, it validates whether the authorization boundary correctly rejects a valid identity when that identity requests a resource outside its assigned policy.
Teleport RBAC uses allow and deny rules, with deny rules taking priority. Teleport roles can also restrict which resource labels and Linux logins an identity can access.
The controlled assessment therefore evaluates whether identity authentication is incorrectly treated as sufficient authorization, or whether Teleport continuously evaluates the authenticated service identity against its assigned resource and access policies. When the service identity attempts to access an unauthorized resource, Teleport's authorization policy should deny the connection.
The remediation focuses on least-privilege role design, resource-label restrictions, permitted-login restrictions, short-lived identity credentials, and continuous authorization validation. Teleport documentation recommends restricting roles to only the resources and permissions required by the workload and notes that resource labels can be used to control which infrastructure resources a bot can access.
The complete Zero Trust security workflow is: Service Identity Creation → Short-Lived Identity Issuance → Role Assignment → Resource-Label Authorization → Legitimate Resource Access → Unauthorized Resource Request → Identity and Policy Verification → Access Decision → Unauthorized Access Denied → Security Event Logging → Policy Validation → Post-Remediation Access Testing.