Terraform, we are a go for launch on the strongDM provider! We are happy to announce that strongDM has officially launched as a Terraform provider. That means that in one single configuration you can spin up a fleet of servers, import them into strongDM, and provision your users access in a matter of minutes.
What is Terraform?
Terraform is an open source tool that aims to break down providers into code, making them simpler and easier to apply and provision, all while increasing automation. It essentially provides a single source or truth as you codify all of your infrastructure into code. And that’s exactly why we chose to integrate with it.
SDM + Terraform
strongDM plays a critical role in the adoption of infrastructure-as-code by making access to that infrastructure ephemeral and automated. That means you can develop a repeatable process for infrastructure access that allows you to focus on the things that matter, rather than having to continually manage something that can be automated. It’s basically applying the same principles that you’ve embraced for DevOps, such as CI/CD, to infrastructure and access.
When used in conjunction with Terraform, you can provision and deprovision infrastructure access the moment resources are deployed or taken offline.
Not to mention that by using strongDM for end-to-end infrastructure access, your security team can feel confident that your infrastructure is secured, controlled, and auditable from the very beginning. 😉
Infrastructure Access as Code, Applied
Let’s go through a quick example of why this approach is so powerful. Think through your workflow to allow the teams to be given infrastructure access at the point of provisioning. For example, let’s say we wanted to provision a web server and a MySQL database. One team may need access to SSH to the web server and MySQL server, and the other may need access to the DB.
Deploying into AWS may look something like this:
In this case, we could easily import those resources into strongDM using the following:
By adding these lines, we’ve imported the MySQL DB and SSH server. You can see that we can use Terraform outputs to import the information easily into strongDM (FYI - for the SSH server, you’ll need to update the ~/.ssh/authorized_keys with the output given for the SSH connection to be fully set up). Finally, we can add additional lines to Terraform to create users and roles, then update those roles with permissions to those resources.
This approach makes it easy to provision and deprovision access in a moment, rather than having to use a manual process. Reduce human error and increase efficiency and security? Talk about a win/win.
With Terraform, strongDM can help you easily integrate into every provider in the workflows you’ve already established. That means you can:
- Quickly deploy strongDM into your environment
- Import existing infrastructure easily into the strongDM platform
- Dynamically provision user or roles and update their access in real time to new infrastructure
- Easily integrate strongDM into existing workflows to make a repeatable programmatic process
- Use Terraform to configure strongDM with Hashicorp Vault
Want to get Started?
To get started using the strongDM Terraform provider, you can find the documentation here. If you’re using AWS, you can find a Quick Start Guide in AWS here. We’d love to see what interesting items you create with Terraform and strongDM. And if you’d like to share with others, we also have a Github contribution page. Let us know what you think!