logoalt Hacker News

notepad0x90yesterday at 7:58 PM1 replyview on HN

This is cool. If it adds session recording and SSO auth support, it can be used as an RDP jumphost.

I've used Azure bastion to do just this, you auth to the azure portal using whatever authentication regime is configured for your tenant, then you rdp into virtual machines from your browser using the local vm login. it handles things like files and clipboards great. But it also supports console sessions in the browser.

I haven't used it with windows/rdp (if it even is supported), but in GCP, their in-browser SSH is the best I've seen so far.

Even for Linux, I've found xrdp to be better than alternatives at times.

The main problem I see this solving (one of many) is the decoupling of the management interface for virtual machines and servers from their service interfaces. not having your web server's management services on the same IP/domain/interface as the http server is a big improvement. Lots of security screw-ups happen because of this entanglement.


Replies

hdgvhicvyesterday at 8:17 PM

I use apache guacamole for this with our OIDC proxy for this purpose

show 1 reply