Every source behind this page, graded. Filter by kind.
A note on how these were read: this session's
network reached GitHub, GitLab, raw source hosts and cloud.google.com directly; the other
hosts were confirmed through server-side web search that returns live page excerpts. Every
URL was located in this session, none cited from memory. The full ledger, one row per
claim with the supporting quote, ships beside this page as sources.md.
Case study
Google2020
Building Secure and Reliable Systems, ch. 5 — Design for Least Privilege
Defines Zero Touch interfaces as removing direct human access to reduce outages,
defines break-glass as a complete authorization bypass, and names the weakness of
multi-party approval: the parties usually share one managed fleet.
Carry forwardHuman access is a reliability problem as much as a security one; design the audit culture, not just the log.
google.github.io/building-secure-and-reliable-systems/raw/ch05.html
Talk
Google / USENIX2019-10
Zero Touch Prod: Towards Safer and More Secure Production Environments
The canonical rule: every production change is made by automation, prevalidated by
software, or triggered through an audited break-glass mechanism. Three doors, and only
three.
Carry forwardUse the three-door test to audit your own access paths; anything that fits none is unowned risk.
usenix.org/conference/srecon19emea/presentation/czapinski
Vendor
Google Cloud2026
How Google protects its production services
Estimates ~13% of Google-evaluated outages preventable or mitigable by Zero Touch
Prod, and states that unilateral access to foundational services is not allowed, even in
emergencies.
Carry forwardTie blast radius to approval: the wider the reach, the more emergency access still needs a second person.
docs.cloud.google.com/docs/security/production-services-protection
Postmortem
NYDFS / Twitter2020-10
Twitter Investigation Report
Over 1,000 people held the internal account tools; entry was a help-desk
impersonation during VPN troubles; at least $118,000 taken; no CISO since December 2019.
Carry forwardThe holder count is the attack surface; a phone-borne credential prompt is hostile by default.
dfs.ny.gov/dfs.ny.gov/reports_and_publications/press_releases/twitter_reporthellip;/Twitter-Investigation-Report.pdf
Postmortem
CircleCI2023-01
CircleCI incident report for January 4, 2023
Malware on an engineer's laptop captured a live, already-authenticated SSO session,
putting the login-time multi-factor check out of the path; the targeted role's
permissions reached production data.
Carry forwardProtect the session and the device for any role that can mint production credentials, not just the login.
circleci.com/blog/jan-4-2023-incident-report
Postmortem
Okta2023-11
Unauthorized Access to Okta's Support Case Management System
A support-system service account's credentials were saved into an employee's personal
browser profile on a managed laptop; customer-uploaded support files held reusable
session material.
Carry forwardThe identity vendor's support plane is inside your trust boundary; monitor your own tenant rather than waiting to be told.
sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause
Postmortem
Cloudflare2024-02
Thanksgiving 2023 security incident
Four credentials out of thousands were missed in a rotation because they were
believed unused; they were live. Remediation rotated ~5,000 credentials and triaged
4,893 systems.
Carry forward"Believed unused" is not dead; rotation is only as complete as the inventory behind it.
blog.cloudflare.com/thanksgiving-2023-security-incident
Postmortem
CISA / CSRB2024-03
Review of the Summer 2023 Microsoft Exchange Online Intrusion
Tokens signed by a 2016 key that was never rotated reached mailboxes of 22
organisations and 500+ people; the board could not establish how the key was taken and
called the security culture inadequate.
Carry forwardDanger equals age times scope; if you cannot rotate a signing key automatically, you do not control it.
cisa.gov/…/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf
Eng blog
GitGuardian2022
Uber Breach 2022 — Everything You Need to Know
Reconstructs the September 2022 incident: after MFA-fatigue plus a social-engineering
call, an administrative credential for the privileged-access tool, stored in a script on
an internal share, opened downstream systems.
Carry forwardGuard the credentials to the access system harder than the systems it fronts; no static admin secrets in scripts.
blog.gitguardian.com/uber-breach-2022
Eng blog
Netflix2021
ConsoleMe: A Central Control Plane for AWS Permissions and Access
One broker across hundreds of AWS accounts, handing out short-lived credentials
through a self-service interface. The build case for centralising the access plane.
Carry forwardShort-lived credentials brokered centrally beat long-lived keys scattered per account.
netflixtechblog.com/consoleme-a-central-control-plane…
Source
Netflix2026
Netflix/consoleme — repository README, archive notice
Archived March 1, 2026 because the open-source version "diverge[d] substantially from
our internal implementations". 3,200+ stars. The half-life of an access broker, in the
maintainer's own words.
Carry forwardAdopting an access broker means owning a fork that drifts; budget for the divergence.
github.com/Netflix/consoleme
Eng blog
Mercari2022-01
Shifting to Zero Touch Production
An organisation outside Google independently adopts the same triad and states the
rule for manual changes: "an approval or audited break glass system should be used".
Carry forwardThe three-door rule is not Google-specific; a mid-size org can adopt it verbatim.
engineering.mercari.com/en/blog/entry/20220126-shifting-to-zero-touch-production
Eng blog
Mercari2022-02
Promote Zero Touch Production — further features of Carrier
Carrier's break-glass grants permissions without reviewer approval in emergencies,
but alarms a dedicated Slack channel on every use and audits it continuously.
Carry forwardMake the emergency door approval-free but loud; the alarm, not the gate, is the control.
engineering.mercari.com/en/blog/entry/20220201-promote-zero-touch-production…
Eng blog
Figma2025-04
Designing for Security and Usability: Figma's Modern Endpoint Strategy
Role-pre-approved just-in-time access via Opal, auto-expiring around an hour, framed
against the anti-patterns burdensome access creates: shadow IT and prod work from
unmanaged environments.
Carry forwardUsability is a security control here; access too painful to get is routed around.
figma.com/blog/figmas-modern-endpoint-strategy
Source
GitLab2026
Runbooks — Teleport Approver Workflow & Rails Console access
A full JIT matrix in the open: managers may approve prod read-only, not read-write;
grants expire after 12 hours; incidents route to on-call. Separately, SREs get the Rails
console "directly without an approval process".
Carry forwardA defensible split: standing access for a small senior group, JIT for everyone else.
gitlab.com/gitlab-com/runbooks/…/teleport_approval_workflow.md
Policy
GitLab2026
Handbook — Teleport Access policy
Okta-driven role baseline plus access requests, quarterly access reviews, and audit
logs retained one year, immutable, with least-privilege access to the audit data itself.
Carry forwardImmutable, time-bounded audit retention is the difference between a log and an audit trail.
handbook.gitlab.com/handbook/engineering/gitlab-com/policies/teleport
Source
GitLab2026-09
Infra tracker #29713 — Streamline Teleport access
Years after adopting a commercial broker, the operator openly asks whether Teleport
"should serve as the default mechanism for granting production access… during
incidents". The negotiation reopening in public.
Carry forwardExpect to revisit the access model every few years; it is never finished.
gitlab.com/gitlab-com/gl-infra/production-engineering/-/work_items/29713
Design record
Kubernetes2023-12
kubeadm #2414 & the v1.29 super-admin.conf split
The default admin credential was demoted because a system:masters
certificate bypasses RBAC and can only be revoked by rotating the cluster CA; the
unrevocable form was moved to a separate file to be treated as break-glass.
Carry forwardKeep the unrevocable super-credential sealed and unused; make the daily driver revocable.
github.com/kubernetes/kubeadm/issues/2414
Source
Teleport (community)2023
Discussion #30686 — What to do if the SSO provider is down?
The vendor's guidance for IdP failure is a standing local user that logs in "without
needing Github at all"; issue #3760 shows users asking for a documented recovery path
since 2020.
Carry forwardThe emergency account must authenticate through a path the IdP outage cannot touch.
github.com/gravitational/teleport/discussions/30686
Vendor
Microsoft2026
Entra ID — Manage emergency access admin accounts
Two or more emergency accounts, at least one excluded from all Conditional Access
policies, phishing-resistant credentials, monitored sign-ins. The mainstream
prescription for the emergency plane.
Carry forwardTwo break-glass accounts, not one; monitor their use as the highest-signal alert you own.
learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access
Practitioner
BeyondTrust2023-10
BeyondTrust Discovers Breach of Okta Support Unit
The customer that treated its identity plane like production flagged the anomalous
session activity within 30 minutes of the support-file upload, roughly two weeks before
the vendor confirmed the breach.
Carry forwardDetection you own beats disclosure you wait for; instrument the identity plane yourself.
beyondtrust.com/blog/entry/okta-support-unit-breach
Practitioner
Doyensec2023-05
Testing Zero Touch Production Platforms and Safe Proxies
A consultancy that assesses these platforms reports no mature off-the-shelf option
exists and flags the approval flow's webhooks (spoofing, weak auth, replay) as the soft
target.
Carry forwardThe approval ceremony's webhooks are attack surface; authenticate and anti-replay them.
blog.doyensec.com/2023/05/04/testing-ztp-platforms-a-primer.html
Talk
R. McCarthy, fwd:cloudsec2024-06
The Path to Zero-Touch Production
A synthesis of incrementally moving a cloud-native org to Zero Touch Prod, framed
around why and how people touch production and what to do about it, with AWS access
primitives.
Carry forwardZTP is reachable incrementally; you do not need Google's scale to start.
speakerdeck.com/ramimac/the-path-to-zero-touch-production
Paper
Oppenheimer et al., USITS2003
Why Do Internet Services Fail, and What Can Be Done About It?
Operator error was the largest single failure cause in two of three large services
studied, with configuration errors the largest operator-error category. The empirical
floor under the whole topic.
Carry forwardReducing human touch is a reliability lever with two decades of evidence, not only a security one.
usenix.org/conference/usits-03/why-do-internet-services-fail-and-what-can-be-done-about-it
Paper
Google, SIGCOMM2016
Evolve or Die: High-Availability Design Principles from Google's Network
Across 100+ high-impact failures, a large share occurred while a management operation
was in progress; ~80% lasted between 10 and 100 minutes. Quantifies the change-path risk.
Carry forwardThe change path, not the steady state, is where operator-driven failure concentrates.
research.google/pubs/evolve-or-die…
Paper
Saltzer & Schroeder1975
The Protection of Information in Computer Systems
The origin of least privilege: "Every program and every user of the system should
operate using the least set of privileges necessary to complete the job." Every design
in this guide implements or violates it.
Carry forwardLeast privilege is fifty years old; the novelty is only in making it low-friction enough to keep.
cs.virginia.edu/~evans/cs551/saltzer
Practitioner
R. McCune2024-01
When is admin not admin?, when it's super-admin!
Independent confirmation of the kubeadm change: system:masters bypasses
RBAC, so super-admin.conf is the unrevocable fallback while admin.conf became revocable.
Carry forwardKnow which of your credentials bypass your own authorization layer; those are break-glass, not daily tools.
raesene.github.io/blog/2024/01/06/when-is-admin-not-admin