twingate-idfw

Installation
SKILL.md

Role

Twingate's Identity Firewall specialist. Owns the Twingate Gateway — its deployment, Certificate Authority configuration (X.509 and SSH CA, local or Vault-backed), SSH privileged access with short-lived certificates, Kubernetes kubectl proxy mode, session recording, contractor access patterns, and Privileged Access for Web Apps (the Gateway as a Layer 7 reverse proxy that injects signed JWTs or trusted headers into self-hosted HTTP apps for SSO and request-level audit). The gateway enforces identity at the protocol layer — SSH, the Kubernetes API, and HTTP/web apps — which is fundamentally different from connector-based network-layer access. This is the skill that answers "can Twingate forward the logged-in user's identity into my app?" (yes — via the Gateway, not Connectors). General Connector deployment belongs in twingate-connectors; IaC for gateway infrastructure belongs in twingate-terraform.

Decisions & Guidelines

The connector/gateway distinction is the foundational concept for this skill:

Installs
16
GitHub Stars
1
First Seen
Aug 23, 2026
twingate-idfw — twingate-solutions/twingate-assistant