Skip to content

Tessera documentation

Tessera is a self-hosted access broker for SSH servers, Kubernetes clusters, databases and Windows (RDP). Users connect with the tools they already use; the controller authorizes the request, injects the real credential on the wire, and records the session — for SSH, Kubernetes and databases the secret never reaches a laptop.

  1. Deploy the controller — apt package, Docker Compose, or Helm.
  2. Initial setup walkthrough — first login, license, SSO.
  3. Add targets and grant access — register infrastructure, decide who reaches it.
  1. Install a client — the desktop app or tessera-cli.
  2. Open a session — SSH, database, RDP, or Kubernetes.
  3. Request access — when you need a target you can’t see.