Build1 distinct publisher3 min readPublished
The mechanism itself is roughly a week of work, using software that already ships with OpenSSH. What follows is harder: custody of a single key that opens every host, and an issuance flow whose requirements keep arriving.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
TrustedUserCAKeys on the target host is the whole trust model, and that is what makes custody non-negotiable [2]. One private key can grant access to every host in the fleet, which is why keeping it on a laptop is described as an incident waiting to happen [3]. So it moves into an HSM or a KMS, and signing stops being a local operation and becomes a dependency with its own availability [4]. Certificates are issued with short validity, so that operation runs constantly [2], which is how you arrive at the author's own description of a system sitting in the path of every production login [9]. That is my reading of why he puts the outage runbook inside the two-to-four week custody estimate rather than somewhere after it [4].
The money is arithmetically consistent, which is worth confirming before you quote it at a review. Two to three engineer-quarters is 0.5 to 0.75 engineer-years [1]. At the bottom of both ranges, 0.5 times $150k is $75k; at the top, 0.75 times $200k is $150k, which reproduces the published $75k to $150k exactly [2]. The ongoing figure works the same way: a tenth of an engineer at $150k is $15k, a quarter at $200k is $50k [3]. Widest honest bracket, no padding hidden in it. The ratio is the part I would carry into the meeting. Two to three quarters is 26 to 39 engineer-weeks, so the week everybody estimates confidently comes to between 2.6% and 3.8% of the total, and it is also the only part of the project that produces a demo [4].
Three things have to hold for those numbers to be yours. Your loaded engineer cost sits in the $150k to $200k band [12]. You actually intend to ship IdP integration and an approval path rather than living with manual approval indefinitely [5]. And you count session audit plus Kubernetes and database access as in scope, because the quarter-of-engineering figure excludes them: audit roughly doubles it, and covering clusters and databases turns the thing into a small internal product with permanent maintenance [10]. If the second condition fails, the build stalls short of completion, and that stall is its own way of blowing the estimate [14].
The disclosure does work here. The estimate comes from someone who sells the alternative [1], and it is one practitioner's judgement rather than measured data from a sample of teams. What makes it usable anyway is which line items grow: the approval path that has no launch date [5], and the on-call rotation for a login-path service [9]. His explanation for why the 80% version persists is the part I would not argue with, that internal tools are funded by attention and attention moves [15]. His gate is four conditions, build if two hold [13]. In my context the audit requirement settles it before the arithmetic does. If an auditor wants per-command history, the comparison is a CA plus a session recording system against the product, and the recording half is the harder engineering [7].
Ranked by verification strength, evidence, and original report placement.
The author discloses that he works on Tessera, which is on the buy side of the comparison, and says he tried to cost the build side properly because a comparison where the build option looks stupid is one nobody believes.
The CA itself is a week of work for a competent engineer: generate a key pair, configure targets with TrustedUserCAKeys, and sign user keys with a short validity. This part works.
The CA private key can grant access to every host in the fleet; on a laptop it is an incident waiting to happen.
Rollout means editing sshd_config on every production host: technically trivial, organisationally not, requiring a change window, sign-off and rollback plan, plus the discovery that some hosts are not in configuration management.
Certificates show that a session was authorised but not what happened in it; per-command history or session replay is a separate system and a much harder one than the CA.
None of the SSH CA work covers Kubernetes cluster access or database credentials, which are separate problems with separate solutions and in most organisations are where the genuinely dangerous access lives.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Teleport puts the developer's Linux desktop inside the audit trail, and takes the SSH keys with it1 distinct publisher
build
A linear conntrack scan holds Cilium pod setup for 80 seconds at Adyen's peak1 distinct publisher
build
SSE in Go breaks twice before your handler runs: an illegal header, then a 30-second timeout1 distinct publisher
build
Rate limit your MCP servers, because a retrying agent turns one error into a billing incident1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interested author, no second voice
Everything rests on a single dev.to post whose author says up front that he sells the alternative. The mechanical spine holds up on its own terms — a CA key that signs for the whole fleet, certificates that attest authorisation and nothing about the session, an SSH project that by definition does not reach Kubernetes or database credentials. The quantities do not: two to four weeks for key custody, months for issuance, two to three engineer-quarters to parity, all offered without a team, a timesheet or a post-mortem behind them.
An estimate, not a deployment
Nothing here has been shipped, measured or invoiced in public. The closest thing to field evidence is the aside that the very large companies all built their own, and it arrives without a company attached. There is no release, no rollout and no bill to weigh the figures against.
Round numbers doing precise work
The dollar ranges are honest arithmetic — the effort range multiplied by the salary range, low against low and high against high — but that only inherits the confidence of the effort range, which is a judgement stated in the register of a quote. Pushing the other way, the author does the unusual thing for a vendor-adjacent writer and lists four situations in which building wins outright. The overstatement is in precision, not in direction.
The buy side costing the build side
The disclosure is in the first line and it matters: an engineer at Tessera is estimating what it costs not to buy Tessera. The tell is the ending, which leaves the build economics behind and argues that per-resource billing grows with every autoscaling event until teams quietly route around the control, while per-seat billing does not — a conclusion about a pricing model rather than about a week of engineering. The framework is worth keeping; the figures should be read as advocacy.
Coherent, unchecked
What this story says, and why it says it, we can read with some confidence: the reasoning holds together and the motive is declared rather than inferred. Confirming it is another matter. No second voice, no named build that reached 80% and stalled, and dev.to alone carrying every figure the argument stands on.