Teleport
Teleport on Lazycat provides a unified access plane for centralized SSH, Kubernetes, database, and internal web app access, leveraging certificate-based authentication and zero-trust policies with MFA, audit logging, session recording, and management through Web UI and CLI tools for secure operations.
## Teleport Unified Access Plane Teleport on Lazycat centralizes secure access to SSH, Kubernetes, databases, and internal web apps with certificate authentication, audit logging, and zero-trust policies. ## Key Capabilities - Certificate-first zero-trust access with built-in MFA and role policies - Web UI, `tctl`, and `tsh` entry points for operations, automation, and CLI workflows - App Service for publishing internal HTTP apps with reserved domain prefixes - Comprehensive auditing and session recording for compliance-ready visibility ## Quick Start 1. Log in to the Lazycat SSH console and run `lzc-docker exec cloudlazycatappliuteleport-teleport-1 tctl users add admin --roles=access,editor`, keeping the invitation link from the command output 2. Open the invitation link in a browser, follow the wizard to set the password and MFA, complete activation, and sign in to the Web UI 2. Visit `https://teleport.{box-name}.heiyu.space` to configure roles, resources, and MFA 3. Edit `/data/appvar/cloud.lazycat.app.liu.teleport/config/teleport.yaml` to enable `app_service` and choose from `prefix/app/node/db/kube/bot/discovery` domain prefixes 4. Export the proxy certificate and CA pin to trust the cluster for local App Service or CLI enrollment 5. Use the Web UI generated Debian installer script to onboard server nodes quickly ## References - Quick Start: https://github.com/lazycatapps/teleport/blob/main/QUICKSTART.md - Docs: https://goteleport.com/docs/ - GitHub: https://github.com/gravitational/teleport







