10 ms·
Google Identity-Aware Proxy
- mcpherrinm 10y agoI'm super happy to see this. Square uses something similar for employee access to our datacenter, and I hope more people follow this trend. It's one of the annoying parts of open-sourcing our infrastructure -- we can't generally assume folks have an authenticating proxy around. With a few examples in the wild, I'll be happy to start doing that. We use mutually-authenticated TLS (ie, the proxy presents a client cert to your backend) so that you know the entire request is valid, including the username header. IAP only signs the header, which could be replayed because it's not bound to the session (eg, a debug page exposes request headers). But it's probably easier to grab a library that can validate JWT than worry about your TLS termination layer (eg, in a rails app behind nginx terminating TLS & serving asssets)
- brazzledazzle 10y agoHave you seen https://github.com/bitly/oauth2_proxy https://github.com/bitly/oauth2_proxy?
- rrdharan 10y agoI love that thing - I use it with nginx to secure access to stuff running on my home machine that I want to expose publicly (e.g. the Transmission Web UI).
- brazzledazzle 10y agoThat's a great use for it I hadn't considered. Thanks for the idea.
- StavrosK 10y agoWouldn't something like Caddy's multipass[1] be easier and with less third-party approval? That said, I just use Caddy to proxy all my home's internal services with basic auth. At work I use the same setup, except it authenticates against our LDAP server. [1]: https://caddyserver.com/docs/multipass https://caddyserver.com/docs/multipass
- chayesfss 10y agoWhat types of webservices? Just pure L7 stuff that has forms on it? Is that oauth2proxy just an authenticated reverse proxy or can it add some security context to the internal interface?
- roque 10y agoWe use it in conjunction with kubernetes service proxy https://github.com/pedro-r-marques/k8s-service-proxy https://github.com/pedro-r-marques/k8s-service-proxy to access all of our internal services and debug ports deployed in the k8s/GKE cluster. oauth2 proxy authenticates, service discovery in k8s means that we can keep publishing apps. We don't use fine grain ACLs... But i guess that we could if we wanted to.
- mcpherrinm 10y agoI hadn't before this thread. It looks cool. I'm definitely going to look into it more. Thanks!
- willejs 10y agoI'm a big fan. Ive been using it to do 'outside in' google type, expose services on the internet via oauth for ages. Its solid and great.
- tracker1 10y agoFor a recent service I wrote, it requires the JWT to expire in less than a minute.. which would at least minimize replay attacks and entirely possible to do something similar. Though client certs is definitely safer all around, more involved to spread around to apps talking to each other though.
- deleted 10y ago[deleted]
- pacala 10y agoHow does this compare/relate with LastPass?
- will_hughes 10y agoOnes a password manager, the other is a proxy. Apples and dump trucks, completely different purposes.
- eeZi 10y agoCan anyone recommend this? https://github.com/bitly/oauth2_proxy https://github.com/bitly/oauth2_proxy
- WestCoastJustin 10y agoI've used it for an internal project and it worked really well. Simple and easy to follow instructions.
- nathancahill 10y agoI've also used it internally, works great.
- cypherpunks01 10y agoIs there any good way to configure it to handle many subdomains with one instance, or do you still have to pick between using one primary proxy.tld vs. running lots of instances of the proxy?
- deleted 10y ago[deleted]
- cloudposse 10y agoYea! It's awesome. We have a kubernetes chart for it available here: https://github.com/cloudposse/charts/tree/master/incubator/oauth2-proxy https://github.com/cloudposse/charts/tree/master/incubator/o...
- alexee 10y agoIs there similar service in AWS?
- Thaxll 10y agoCognito I think. https://aws.amazon.com/cognito/ https://aws.amazon.com/cognito/
- brazzledazzle 10y agoCan cognito act as a reverse proxy?
- kyrra 10y agoAs you can sort-of see from the linked site, this is a public version of what Google uses internally, which is called BeyondCorp[0]. It's really an amazing way to think about security for a company. If you deploy it universally across your company, VPNs become obsolete. This solves a popular attack vector where bad-actors just need to get onto a corporate network to do damage. If you can authenticate at every service your employees connect to, it closes down that vector. [0] https://cloud.google.com/beyondcorp/ https://cloud.google.com/beyondcorp/
- hdhzy 10y agoAs far as I remember BeyondCorp required users to be equipped only with attested hardware (no BYOD). This device's health then was constantly being monitored and taken into account when granting / denying access. I'd like to see the differences between IAP and Google's internal BeyondCorp. Quick search did not reveal anything.
- wffurr 10y agoThe only BYOD device allowed is Chromebooks with a signed bootloader, aka no developer mode or Crouton.
- kuschku 10y agoUnless you modify the hardware, of course. Considering Google has teams designing custom PCBs and even ICs, there's a non-insignificant amount of Google devs who could easily circumvent this entire system.
- londons_explore 10y agoGoogle's model requires two factor user auth, and trusted hardware. Even someone with serious hardware-foo would only be able to maybe break the trusted hardware bit (by cloning one device id to another, or emulating a device). They couldn't get round the two factor authentication bit. I'd say it's still a pretty watertight model.
- dzhiurgis 10y agoWhat is a difference between proxy and a VPN?
- schoen 10y agoTraditionally a VPN operates at the IP layer, while a proxy operates at the application layer. For example, a VPN will provide an IP route that you can send any kind of packets over, while an HTTP proxy speaks the actual HTTP protocol and makes HTTP requests on your behalf.
- mcpherrinm 10y agolayering differences aside, there's a fairly important security difference here: Because the proxy is examining requests, it can authorize them, and provide data to the back-end about what user was authenticated. A VPN usually just gets you onto the network, and doesn't provide much if any data to the service being accessed about what user and application is connecting. A VPN is generally invisible to both sides of the communication, so you can tack on extra security, but it's harder to have the applications actually rely on it for authn/authz guarantees. In practice this means you have to log in twice: Once to the VPN, and again to the application. There's some ways to make that invisible to the user, though.
- cobookman 10y agoLets you have a whitelist of accounts per serivce. for example your HR payroll site can have IAP sitting in front of the site. IAP can only allow managers & hr access where-as the underlying system might not have this identity protection. You can then have different whitelists per service. Also IAP doesn't require the use of a VPN client. All one needs is a web browser with an internet connection. Giving your workers freedom to access corp assets just about anywhere.
- nunez 10y agoVPNs are also much more expensive to maintain (good VPN hardware isn't cheap), introduce much more network latency and are another thing for help desk personnel to have to support (read: spend money supporting). BeyondCorp/UberProxy is just a really complicated whitelist. That's it. Super simple.
- fortyfivan 10y agoHappy to see BeyondCorp start to catch on. We've been champions for a while at ScaleFT. In fact, we're hosting a BeyondCorp Meetup tonight in SF. There will be a couple talks on the subject that should be of interest to folks here. It's an open event with RSVP, so come by if you're around. https://www.meetup.com/BeyondCorpSF/events/238062984/ https://www.meetup.com/BeyondCorpSF/events/238062984/
- derefr 10y agoDoes this serve a similar function to e.g. https://getkong.org/ https://getkong.org/ ?
- fowl2 10y agoThoughts on how this compares to something like Azure AD Application Proxy? Seems cheaper at least!
- AlphaWeaver 10y agoSeems like a cool service, but not really a fan that the acronym mirrors a different service from AWS (Identity and Access Management.) Could be confusing.
- deepsun 10y agoBecause Google Cloud already has had IAM for some time: https://console.cloud.google.com/iam-admin/iam https://console.cloud.google.com/iam-admin/iam As with AWS IAM, it manages access to the infrastructure, like your machine instances. But this new Google thing, as far as I understand, is about giving other (potentially non-technical) users access to your corporate resources using single identity.
- sidcool 10y agoIf this really works as they claim, it's a big reprieve from the VPN crap I have been dealing with since years.
- hobbified 10y agoOh, did this just launch today? That's funny, I thought I only noticed it today. In any case, I'm using it already. I was going to build SAML into this app that we have deployed on GCE, so that employees can access it over the internet as long as they're authenticated, but instead I put it behind an IAP, and our Google auth already talks to our SAML server, so Google is effectively doing the same work for us.
- esseti 10y agoCan someone list a Use Case? I don't get it much how I should use this service. Should I connect to it to have access to server? remote machines? or be inside a network? Or should/could It be used to authorize users of a service to access determinated urls of a web app?
- mixedbit 10y agoIf anyone needs something like this for Heroku, you check my add-on: https://elements.heroku.com/addons/wwwhisper https://elements.heroku.com/addons/wwwhisper