Back to articles
Technology Insight

Architecting Zero Trust Access for SSH: A Comprehensive Guide to Deploying Teleport on a VPS

June 3, 2026

The Paradigm Shift: Moving Beyond Traditional SSH

For decades, Secure Shell (SSH) has been the gold standard for remote server administration. However, the traditional model of SSH access—relying on static cryptographic keys, passwords, and open port 22—is increasingly becoming a liability in the modern threat landscape. Lost keys, unmanaged access rights, lateral movement risks, and the lack of granular audit trails create significant vulnerabilities for enterprise infrastructure.

As organizations scale, managing public keys across dozens or hundreds of Virtual Private Servers (VPS) becomes an operational nightmare. Enter Zero Trust Architecture (ZTA), a security framework rooted in a simple principle: never trust, always verify. To bring Zero Trust to infrastructure access, engineering teams are turning to Teleport, an open-source, identity-aware access gateway that replaces static SSH keys with short-lived, ephemeral certificates tied to centralized identities.

Understanding Teleport and the Zero Trust Philosophy

Teleport functions as a centralized proxy for your infrastructure. Instead of connecting directly to a VPS, administrators and developers authenticate against the Teleport Access Plane. Once authenticated, Teleport issues short-lived certificates that automatically expire, eliminating the risk of orphaned or stolen credentials.

When deploying Teleport on a VPS to secure SSH access, you unlock several enterprise-grade capabilities:

  • Identity-Based Access: Integration with Single Sign-On (SSO) providers like Okta, Azure AD, or GitHub to enforce multi-factor authentication (MFA).
  • Zero Exposed Ports: The target servers do not need to expose port 22 to the public internet; they communicate with the proxy via secure reverse tunnels.
  • Complete Auditability: Every SSH session is recorded, and every command executed is logged in a centralized, tamper-proof audit trail.
  • Role-Based Access Control (RBAC): Define precise policies determining who can access which servers and under what conditions.

Prerequisites for Deployment

Before initiating the installation, ensure you have the following components ready:

  1. A Linux-based VPS (e.g., Ubuntu 22.04 LTS or Debian 12) with a public IP address.
  2. A registered domain name (e.g., teleport.yourcompany.com) with A records pointing to your VPS IP.
  3. Ports 443 (HTTPS) and 3023/3024 (Teleport proxy traffic) open on your cloud firewall.

Step-by-Step Architecture Implementation

Step 1: Installing the Teleport Binary

First, update your package repository and install the official Teleport repository on your VPS. For an Ubuntu system, execute the following commands:

sudo curl [https://goteleport.com/gpg/key.pub](https://goteleport.com/gpg/key.pub) -o /usr/share/keyrings/teleport-archive-keyring.asc
echo "deb [signed-by=/usr/share/keyrings/teleport-archive-keyring.asc] [https://apt.goteleport.com/](https://apt.goteleport.com/) ubuntu stable main" | sudo tee /etc/apt/sources.list.d/teleport.list
sudo apt-get update
sudo apt-get install teleport

Step 2: Configuring the Teleport Service

Teleport requires a configuration file, typically located at /etc/teleport.yaml. You can generate a baseline configuration using the Teleport tool itself, which will automatically request a Let's Encrypt SSL certificate for your domain:

sudo teleport configure --cluster-name=teleport.yourcompany.com --public-addr=teleport.yourcompany.com:443 --cert-file=/var/lib/teleport/fullchain.pem --key-file=/var/lib/teleport/privkey.pem --acme [email protected] -o /etc/teleport.yaml

This configuration establishes the Auth Service and the Proxy Service on your VPS, enabling secure web UI access and routing traffic through a single port.

Step 3: Starting the Service and Creating the Cluster Administrator

Enable and start the Teleport daemon using systemd to ensure it runs continuously and restarts on boot:

sudo systemctl enable teleport
sudo systemctl start teleport

With the service running, create your initial administrative user. This user will have the authority to configure RBAC roles and invite other team members:

sudo tctl users add admin --roles=editor,access --logins=root,ubuntu

The output of this command will provide a unique, time-sensitive URL. Navigate to this URL in your web browser to configure your password and setup hardware-based MFA or an authenticator app.

Enforcing Node Security via Reverse Tunnels

One of the most powerful features of a Zero Trust SSH setup is the elimination of direct ingress paths. To add additional backend VPS instances to your cluster, you do not open their SSH ports to the world. Instead, you generate a secure join token on your main Teleport proxy:

sudo tctl tokens add --type=node

On the target node, install the Teleport binary and configure it as a pure SSH Service pointing back to your proxy URL using the generated token. The node will establish an outbound secure reverse tunnel. When an engineer requests an SSH session, Teleport routes the traffic through this internal tunnel, ensuring the node remains entirely invisible to internet port scanners.

Auditing, Session Recording, and Compliance

From a governance perspective, traditional SSH falls short due to fragmented logs stored locally on individual machines. Teleport centralizes visibility. When a user connects via the tsh ssh command-line tool or the interactive web-based terminal, Teleport records the entire lifecycle of the session.

Security officers can review live sessions in real-time or replay past sessions step-by-step to investigate anomalies. Every command, file transfer, and network connection initiated during the session is logged, fulfilling strict compliance requirements such as SOC 2, ISO 27001, and PCI-DSS.

Conclusion: Future-Proofing Infrastructure Access

Transitioning from traditional public-key authentication to a Zero Trust SSH model with Teleport drastically reduces your organization's attack surface. By centralizing authentication, automating certificate issuance, and eliminating public-facing SSH ports, you effectively neutralize credential-stuffing attacks and brute-force attempts on your VPS infrastructure. Implementing this architecture is a definitive step toward modern, resilient, and compliant infrastructure engineering.

Architecting Zero Trust Access for SSH: A Comprehensive Guide to Deploying Teleport on a VPS | DPTCloud