figma

Inside Figma: getting out of the (secure) shell | Figma Blog (opens in new tab)

Figma replaced its traditional bastion-host SSH model with a zero-trust shell-access system built on AWS Systems Manager Session Manager. The design combines Okta, AWS SSO, phishing-resistant WebAuthn MFA, short-lived IAM credentials, and centralized session logging. This eliminated exposed SSH ports while making access easier to manage, audit, and roll out incrementally.

Why Figma moved beyond bastion hosts

  • Bastion hosts became increasingly difficult and time-consuming to secure and manage as Figma scaled.
  • Because bastions are critical security controls, attackers may target them to gain access to production systems and user data.
  • Figma’s replacement aimed to provide:
    • A smooth and reliable developer experience
    • Zero-trust networking
    • Strong authentication and phishing-resistant MFA
    • Short-lived, automatically rotating credentials
    • Centralized auditing and session tracing
    • Minimal operational maintenance
    • Incremental, backwards-compatible adoption

Choosing AWS Systems Manager

  • Figma evaluated commercial products such as Okta Advanced Server Access.
  • These products lacked flexibility for existing workflows, were not always available to Figma, and could introduce external availability dependencies.
  • Since Figma already relied heavily on AWS, the team built a proof of concept using AWS services.
  • Systems Manager Session Manager provides:
    • Authenticated, encrypted TLS connections between users and managed instances
    • Interactive shells and command execution
    • SSH tunneling when needed
    • Access to EC2 and ECS without exposing SSH ports or making instances externally reachable
    • Centralized permission management through IAM roles

SSO, authentication, and access control

  • Okta integrates with AWS SSO to provide centrally managed authentication.
  • Figma requires device trust and WebAuthn-based multi-factor authentication.
  • Authenticated users assume dedicated, minimally privileged IAM roles.
  • AWS access tokens are short-lived, limiting the impact of stolen credentials.
  • Session Manager records session transcripts in an encrypted S3 bucket for investigation and auditing.
  • Okta group synchronization makes access management straightforward for IT teams.
  • Engineers can start sessions either through the AWS Systems Manager console or through Figma’s custom command-line tool.

Mitigating AWS SSO phishing risks

  • AWS SSO can be abused through device-code phishing, where attackers trick users into approving an authorization request created by the attacker.
  • Figma added monitoring and alerts to detect suspicious authentication activity.
  • Engineers are also expected to treat unexpected SSO authorization pages as suspicious.

Setting up Session Manager

  • AWS provides configuration guides for both EC2 and ECS.
  • Figma’s approach uses Session Manager as the secure access layer while relying on IAM policies, SSO groups, and encrypted logging to control and audit sessions.
  • The system preserves existing workflows where necessary while removing the need for publicly accessible SSH infrastructure.

Figma’s experience suggests that teams already invested in AWS can build a practical zero-trust shell-access system with native services. Session Manager, combined with strong SSO controls, least-privilege IAM, short-lived credentials, and centralized logging, offers a simpler and more secure alternative to bastion-based SSH.