TrademarkTrademark
Features
Documentation

Introducing Scalr's "Break the Glass" Feature: Ensuring Emergency Access for AdministratorsSMASH GLASS, GET IN CAVE: EMERGENCY DOOR FOR CHIEFS

An overview of the latest feature designed to help administratorsWhen magic door break, chosen chiefs smash glass and enter cave anyway. Caveman explain how.
Alistair HeysAugust 18, 2022
Introducing Scalr's "Break the Glass" Feature: Ensuring Emergency Access for Administrators

When something breaks, the last thing you want is to be locked out of the system you need to fix it. Scalr built the "Break the Glass" feature for exactly that situation, so administrators can still get in during an incident.

The "Break the Glass" feature allows selected users to bypass the regular Single Sign-On (SSO) process and log in directly using their administrator credentials. By being exempt from the IDP login restrictions, these privileged users can swiftly address any emergencies that may arise, ensuring minimal disruption to your operations.

A few guidelines will help you use the feature well:

  1. Configuration with Care: The user responsible for configuring the SSO should be included in the "break the glass" list. This inclusion ensures that in case of any misconfigurations, such as accidental lockouts, you have a failsafe mechanism to regain access and rectify the issue promptly.
  2. Preparedness for IDP Downtime: IDP providers occasionally experience downtime or encounter configuration issues, such as expired SAML certificates. During these scenarios, regular users may face login restrictions. Having designated "break the glass" users enables uninterrupted access, so they can update configurations or perform critical actions even when the IDP is down.
  3. Secure Emergency Access: While the "break the glass" feature provides essential emergency access, it's important to exercise caution when granting these privileges. Limit the number of users on the list to only those who truly require this level of access. Additionally, ensure that the accounts associated with these users have security measures in place, such as strong passwords and multi-factor authentication.

With "Break the Glass" set up ahead of time, an IDP outage or a botched SSO change doesn't lock your team out of Scalr. Add a couple of trusted admins to the list now, secure their accounts, and you have a way back in when you need it.

To learn more about this feature and what Scalr can do for your organization, sign up today!

When cave on fire, chiefs must get inside cave. No excuses. That why Scalr build "Break the Glass" — special emergency entrance made just for tribe chiefs.

Normal tribe members enter cave through magic SSO door (identity spirit check who you are, then open door). "Break the Glass" let chosen chiefs skip magic door and enter with their own chief password instead. When magic door break, chosen chiefs still get in, fix problem fast, tribe keep hunting.

But emergency door must be set up wisely. Caveman share three rules from elders:

  1. Door builder must hold spare key: Chief who set up the SSO door must be on break-the-glass list. Why? If chief fumble door setup and lock whole tribe out, chief can still get in and fix own mistake. No spare key, no fix. Tribe stand outside cave in rain.
  2. Magic door spirits get sick sometimes: Identity spirit (IDP) sometimes go down or door magic expire (SAML certificate become old and die). When that happen, normal tribe members stuck outside. Break-the-glass chiefs still get in, renew the magic, push important rocks even while spirit sick.
  3. Few keys, strong keys: Emergency door powerful, so be careful who get key. Only give to chiefs who truly need it. And chiefs with keys must guard them hard — strong password, multi-factor grunt check. Key falling into wrong hands very bad for tribe.

With Break the Glass, tribe ready for surprise disasters. Cave stay reachable, work keep moving, chiefs sleep well on rock pillow.

Want learn more about what Scalr do for tribe? Sign up today!

About the author
Alistair HeysVP of Marketing at Scalr
Alistair Heys is the VP of Marketing at Scalr, writing about Terraform, OpenTofu, and infrastructure-as-code platform engineering for DevOps teams.