Case Study: Flywheel cuts engineer access setup from three weeks to about 20 minutes with Teleport
Key results
The challenge
Flywheel's platform runs inside customers' cloud and data-center environments, and each engineer needs access to every assigned customer environment. Onboarding a new engineer to a customer environment could take up to three weeks because of setting up MFA, passwords, and repeated back-and-forth requests with clients' IT teams. Flywheel also had to maintain HIPAA, GDPR, and Institutional Review Board compliance while protecting patient medical imagery.
The solution
Flywheel adopted Teleport Enterprise as its access solution across AWS, Google Cloud Platform, Microsoft Azure, and on-premise data centers. Teleport is used as an Identity-Aware Access Proxy providing a persistent reverse tunnel into the Kubernetes environment, which eliminated the need to run a separate bastion service. This replaced Flywheel's previous, more complex bastion-based setup.
“As long as we can deploy Kubernetes, we can run Flywheel in a customer's environment. With Teleport, we can hop into the deployment, access our regular tool set, and operate against the customer's cluster. It provides speed without sacrificing security.”
DFDan FredellPlatform Team Lead, Flywheel
The results, in context
With Teleport, work that once took three weeks or more was cut to approximately 20 minutes. Eliminating the separate bastion service removed a cost the company cites at $200 per bastion per month. Flywheel reports it can deploy to a customer environment about three weeks sooner because access is faster.