Tessera documentation
Tessera is a self-hosted access broker for SSH servers, Kubernetes clusters, databases and Windows (RDP). Users connect with the tools they already use; the controller authorizes the request, injects the real credential on the wire, and records the session — for SSH, Kubernetes and databases the secret never reaches a laptop.
Set up Tessera
Section titled “Set up Tessera”- Deploy the controller — apt package, Docker Compose, or Helm.
- Initial setup walkthrough — first login, license, SSO.
- Add targets and grant access — register infrastructure, decide who reaches it.
Connect to a target
Section titled “Connect to a target”- Install a client — the desktop app or
tessera-cli. - Open a session — SSH, database, RDP, or Kubernetes.
- Request access — when you need a target you can’t see.
More information
Section titled “More information”We would like to count visits with Google Analytics, which needs a cookie. Nothing is loaded and nothing is stored unless you accept. What this sets.