
5/30/2023
What this post added
This post details the implementation of Just-In-Time (JIT) access for engineers to Temporal's infrastructure, specifically focusing on access hours and reducing the overall time users have elevated permissions. It quantifies the security benefits of limiting access to only when needed, highlighting a reduction from 100% access time to approximately 23.8% of the week, and further potential reductions based on actual usage. The post also discusses the security implications of daily rotating AWS access tokens and the benefits of implementing approval workflows for access requests, all contributing to a stronger security posture by reducing the attack surface and making it harder for attackers to exploit compromised credentials.