Skip to content
Suiunbek Isaev
All case studies

Case study

Modernizing Infrastructure Authentication

Moving automation service accounts off direct root SSH-key access across hundreds of AAP job templates and playbooks, with zero business impact.

Result
Hundreds of templates migrated off root SSH keys with zero business impact
Role
Led
Where
Capital One · 2025 – Present
Key stack
Ansible Automation Platform · Ansible playbooks · AAP credentials · Linux / RHEL

Sanitized case study based on professional experience. Internal names, accounts, hostnames and configurations are intentionally omitted.

01Problem

Automation service accounts reached managed servers through direct root SSH-key access. That pattern did not meet company security standards.

02Context

Hundreds of AAP job templates and playbooks depended on the existing access pattern. Application teams relied on that automation every day, so the change had to be invisible to them.

03Architecture

Sanitized conceptual architecture based on professional experience.

How it works

  • Previously, automation logged in directly as root using long-lived SSH keys.
  • Now, automation authenticates as a managed service account whose credentials are held in the AAP credential store, and it escalates privileges only through controlled mechanisms.
  • Job templates and playbooks were updated to the new pattern without changing what they do for application teams.

04Engineering approach

  1. Inventoried the job templates and playbooks that depended on direct root access.
  2. Defined the target access pattern: managed service-account credentials with controlled privilege escalation.
  3. Updated hundreds of templates and playbooks, validating in lower environments before production.
  4. Sequenced production changes through change management to avoid disrupting teams.

05Security

  • Long-lived root SSH keys are hard to rotate, attribute and audit, so removing them shrinks the attack surface.
  • Access is now tied to managed credentials that can be rotated and scoped centrally.
  • The new pattern aligns automation access with company security standards.
  • Actual service-account names and authentication configuration are deliberately omitted.

06Automation

  • Bulk update of job templates and playbooks to the new credential pattern.
  • Validation runs to confirm behavior was unchanged.

07Results

  • Updated hundreds of AAP job templates and playbooks.
  • Removed direct root SSH-key access for automation service accounts.
  • Zero impact to the business.

08Lessons learned

  • Security migrations succeed when the users of the system never notice them.
  • Inventory first: most of the risk sits in the templates nobody remembers.

09Skills & technologies

Identity & accessSecurity remediationAnsibleChange management
Ansible Automation PlatformAnsible playbooksAAP credentialsLinux / RHELSSHPrivilege escalation