Donate to support Ukraine's independence.
Generated by AI

Identity-Driven Access to Internal Resources Using AWS SSM. Part 1: Zero-Trust Port Forwarding

Identity-Driven Access to Internal Resources Using AWS SSM Port Forwarding and ABAC Traditional access to private AWS infrastructure usually relies on VPN connectivity and direct subnet reachability. It works, but it also increases attack surface, enables lateral movement, and makes auditing harder. This article describes a different approach: An identity-driven, zero-trust access model built on: AWS IAM Identity Center (SSO + MFA) (Optional) AWS Systems Manager Session Manager port forwarding Attribute-Based Access Control (ABAC) No direct subnet access. No shared passwords. No SSH key distribution. ...

February 26, 2026 · 9 min · 1715 words · Serhii Kaidalov