Infrastructure access control

Who can reach
production right now?

Most teams can only guess. Credentials get shared, people who leave keep their keys, and when something breaks there’s no clean record of who touched what. GoInfra turns access into something you can see, verify, and trust: every request, every grant, on the record.

✓ Verified on every request
✓ Permanent audit trail
✓ Static VPN per user
Scroll
The signature view

Access is decided against real machines.

Your infrastructure lives in GoInfra as a navigable tree: project, VPC, subnet, down to the individual VM. Grants are made against the real topology, not an abstract list of resource names.

Infrastructure2 projects
gocomet-prod3 vpc
prod-vpc-110.4.0.0/16
db-subnet10.4.2.0/24
pg-primary10.4.2.11
pg-replica-110.4.2.12
app-subnet10.4.3.0/24
api-gateway10.4.3.7
worker-0310.4.3.21
edge-subnet10.4.5.0/24
bastion-0110.4.5.2
gocomet-staging2 vpc
LIVE
Access decision
pg-primary10.4.2.11
gocomet-prod / prod-vpc-1 / db-subnet · PostgreSQL primary
Who can reach this machine3 principals
AR
arjun.kumar
vpn 10.8.0.14 · via role
super adminfull
PR
priya.sharma
vpn 10.8.0.22 · via override
viewerread
ON
oncall-bot
vpn 10.8.0.40 · via service
serviceread
Verified against the database · just now
project → vpc → subnet → vm
Grants map to the real topology, not resource labels.
per-VM
Access is granted or revoked at the individual machine.
no abstraction
What you see in the tree is what exists in the cloud.
The access model

Nothing is trusted from a cached token.

Access is verified against the database on every single request. Sign-in is Google, restricted to your company domain. Three roles set the baseline, and per-user overrides handle the exceptions.

viewer
infra admin
super admin
+ overridegranular control, per user
Request · req_8f2a100
01Google identitymaya.chen@gocomet.com
02Domain allow-listgocomet.com
03Role lookupsuper admin
04Per-user overridenone
05VM grantpg-primary
decisionALLOW · read+write
Live sessions

See who’s connected. Cut anyone instantly.

Every VPN user gets a static IP and can have their devices bound by MAC. Live sessions show who is connected, for how long, and how much data they have moved, in real time. Any session can be cut on the spot.

3 connected
UserMachineVPN IPDurationData
AN
analytics-ro
viewer
pg-replica-1
10.4.2.12
10.8.0.3305:15:209.70 GB ↓
cut
MA
maya.chen
super admin
pg-primary
10.4.2.11
10.8.0.1400:42:111.40 GB ↑
cut
DE
dev.kumar
viewer
api-gateway
10.4.3.7
10.8.0.2202:11:20330 MB ↓
cut
SA
sam.ortiz
infra admin
bastion-01
10.4.5.2
10.8.0.1900:06:5212 MB
ended
The record

Every action, on record. Permanently.

Grants, revocations, role changes, logins, config downloads: each one recorded with who did it, what they did, who it was done to, and the full before and after. The log is filterable, expandable, and append-only.

GrantRevokeRole changeLoginConfig download
AUDIT LOGappend-only
Access granted
sneha@gocomet.com → DB-01
13:42:11 UTC
Role changed
arjun@gocomet.com → infra_admin
13:41:02 UTC
VPN config downloaded
sneha@gocomet.com
13:39:47 UTC
Access revoked
neha@gocomet.com → cache-01
13:37:18 UTC
Why this exists

Built quietly,
end to end.

GoInfra didn’t come out of a roadmap review. It came from the same access mess most infra teams quietly live with: shared credentials, stale grants, no clean record of who touched what, and a decision to just fix it properly instead of working around it again.

No new team, no new budget line. Just the existing pieces (access, audit, VPN) rebuilt so they hold together end to end, and kept that way one careful commit at a time.

What we optimized for
Clarity
Every grant traces to a person and a reason.
Reversibility
Access can always be cut, cleanly, in one step.
Boring reliability
No cleverness where a plain audit trail will do.
Trusted internally
0+

engineers managed through GoInfra

Get started

Make infrastructure access accountable.

Sign in with your company Google account. Access is verified the moment you arrive, and every moment after.

Restricted to your company domain · no shared credentials
GoComet

Infrastructure access control