Customers

Lumistry Manages Thousands of Remote Raspberry Pis with Pangolin

Lumistry builds a robust suite of patient engagement solutions for pharmacies. Using Pangolin, Lumistry provides secure SSH and HTTP remote access to thousands of embedded linux devices - Raspberry Pis - out in the field to their engineering and support teams.

Challenge

Lumistry has deployed thousands of Raspberry Pi embedded Linux devices to customer environments. They sit behind firewalls Lumistry does not control, geographically distributed across the country. In addition, they have thousands of cloud-based virtual machines performing similar business logic. For their team of support personnel and engineering experts, they needed a unified system, tied to their existing identities, to get SSH access to manage and troubleshoot these instances that was end to end encrypted to work within their strick HIPAA framework.

You've demonstrated you'll listen. You've demonstrated responsiveness and reactivity and that you care about the product and the customer. You guys have done glorious work.

Ben BrownSenior Manager Enterprise Technical Operations

Solution

Pangolin delivered an all-in-one remote access hub that provides identity-based, context-aware connections to all of the remote systems. It ties directly into their identity provider, so support and engineering staff authenticate with the credentials and roles they already have rather than a separate set of SSH keys. Using the CLI with basic pangolin ssh resource commands, they were able to quickly and easily roll out SSH access across thousands of devices without distributing, tracking, or rotating individual keys by hand. Each device behind a customer firewall creates an outbound tunnel and becomes just another resource reachable through the nearest site. Additionally leveraging private HTTPS resources they were able to expose internal on device dashboards while still keeping the connection end to end encrypted.

Impact

  • SSH access to 3,100+ remote Raspberry Pis and cloud virtual machines without distributing or rotating static SSH keys
  • Support and engineering teams reach devices through the same central IDP roles they already use, with access revoked instantly when someone changes teams
  • Devices sitting behind firewalls Lumistry doesn't control are reachable without coordinating inbound access with the customer's network team
  • Engineers troubleshoot directly with pangolin ssh instead of routing through shared jump hosts

I was sort thinking about Pangolin as a fancy overlay network. But you’re solving the problem much more elegantly. I think it ticks all the checkboxes.

Ben BrownSenior Manager Enterprise Technical Operations