iac.htora.dev · security templates

Home/Templates/Emergency access that works when login is broken

Emergency access that works when login is broken

A separate account that does not depend on your identity provider, and shouts every time it is used.

Terraform

Why bother

Emergency accounts fail two ways. They sit behind the same single sign-on that just went down, or they work quietly and nobody notices they were used. This sets up an account outside the normal login path, with an alert on every sign-in.

How you know it worked

Sign in with it. An alert should reach the on-call channel.

Not written yet

No code exists for this one. It is listed so the gap shows on the coverage table. When it is written, each platform will use:

PlatformService
AWSA standalone IAM user with a hardware key and a CloudTrail alarm
AzureA cloud-only account excluded from conditional access, with a sign-in alert
Google CloudA dedicated super admin with a log-based alert
Oracle CloudA local user outside the federated domain

Registry 0.6.0. Built 2026-09-22.

Made by Habibullah Tora. Code under the MIT licence, writing under CC BY 4.0.