Tanflow IAM Suite & PAM - enterprise identity and privileged access security for the modern enterprise. Get a Demo →

13 March 2025 · Site Administrator

One Gateway for SSH, RDP, Kubernetes and Databases: Universal Protocol Access in Tanflow PAM

Privileged access fragments across terminal emulators, RDP clients, kubectl and a dozen database tools - each a separate control gap. This article examines Tanflow PAM Universal Protocol Access, one recorded browser gateway for all of them.

Walk past an infrastructure engineer's screen and count the tools: a terminal emulator full of SSH profiles, an RDP client with saved connections, kubectl configured with production contexts, and two or three database GUIs holding credentials for systems of very different sensitivity. Each tool is a separate doorway into critical infrastructure. Each stores its own credentials, keeps its own (usually nonexistent) records, and answers to no common policy. Privileged access governance fails not at any one door but in the sprawl of them.

The enterprise challenge: every protocol its own regime

Heterogeneous estates create heterogeneous access. Linux fleets are reached over SSH; Windows servers over RDP; legacy network devices still answer on Telnet; Kubernetes workloads are entered through kubectl exec; and the databases - MySQL, PostgreSQL, SQL Server, MongoDB - each attract their own client tooling. Any control implemented for one channel leaves the others open: an SSH jump host does nothing for database GUI connections, and session recording bolted onto RDP says nothing about what happened inside a kubectl exec shell. Attackers, and auditors, both find the uncovered channel.

Why per-protocol point solutions multiply cost

The piecemeal response - a bastion for SSH here, an RDP broker there, database activity monitoring somewhere else - produces a museum of partial controls: different policies, different log formats, different consoles, different gaps. Integration work grows with the square of the tools, and the composite picture an investigation needs ("show me everything this admin touched yesterday") requires stitching together sources that were never designed to align.

The Tanflow approach: one gateway, every doorway

Tanflow PAM's Universal Protocol Access renders privileged sessions to the whole estate through one browser-based gateway. The published protocol coverage spans SSH for servers and network devices, RDP for Windows desktops, VNC for remote consoles, Kubernetes kubectl exec, Telnet for legacy devices, SFTP for file transfer, HTTPS web admin consoles, and SQL and NoSQL sessions across MySQL, PostgreSQL, MS-SQL and MongoDB - with support for more than fifteen database CLI and GUI clients, and coverage described as expanding.

Because every protocol traverses the same gateway, every session inherits the same control chain regardless of its type: portal authentication with MFA or federated SSO, policy authorisation to the specific target, credential injection from the vault, real-time command control, and full recording into the tamper-evident audit store. A kubectl exec into a production pod is governed exactly like an SSH session to a production host - same policy engine, same evidence format, same replay console.

The zero-agent property compounds the benefit: none of this coverage required installing anything on the Linux fleet, the Windows servers, the network devices or the Kubernetes nodes. A protocol is covered because the gateway speaks it - which is also why legacy Telnet-only equipment, usually the least governable access in the estate, comes under full control the day it is routed through.

What consolidation looks like operationally

  1. An engineer signs in to the PAM portal once and sees the targets they are authorised for - servers, desktops, devices, clusters, databases - in one place.
  2. Clicking any target opens the appropriate session in the browser: a terminal, a desktop, a database session - credentials injected, never displayed.
  3. Policy and recording apply uniformly; the engineer's local machine holds no credentials, no connection profiles, no client software.
  4. An investigator later asks for everything that engineer touched in a week and receives one chronological, replayable answer.

Enterprise scenario

Consider an IT services organisation whose engineers administer client environments spanning Linux, Windows, network gear and multiple database platforms. Before consolidation, each client engagement meant distributing credentials into a half-dozen tools per engineer - and retrieving them imperfectly at roll-off. Through the gateway, an engineer's access is a set of portal entitlements: granted per client, exercised in recorded browser sessions, and revoked in one action when the engagement ends. The client's auditors get per-session evidence; the MSP's laptops hold nothing worth stealing.

Security and audit implications

Uniform coverage produces uniform evidence - one audit store answering for the entire privileged estate rather than a channel-by-channel patchwork with a gap where the auditor will look. It also removes the credential-scatter problem at its root: when no client tool needs stored credentials, endpoint theft loses its richest target. Database session coverage deserves particular note, as command-level control over SQL sessions is a capability Tanflow's comparison identifies as largely missing from open-source stacks and limited in legacy suites.

Conclusion

Privileged access cannot be governed one protocol at a time; the estate is too plural and the gaps too findable. Tanflow PAM's Universal Protocol Access closes the sprawl into a single controlled, recorded gateway - so that whether the doorway is SSH, RDP, kubectl or a SQL prompt, the rules and the record are the same.

← All posts

See the platform behind the posts

Tanflow IAM Suite and PAM - on your infrastructure, live in 2-4 weeks.