The post prescribes an on-demand SSH gateway pod. It uses short-lived, identity-bound credentials and Kubernetes RBAC to grant scoped, auditable debug sessions.
It recommends an access broker that binds Roles to groups, issues ephemeral certs and OpenSSH user certificates, rotates CAs, enforces command-level policy, limits session scope, and records gateway and API audit logs.









