7 ms·
Hey HN, we (gravitational) are pretty excited about this release. We'll be monitoring the thread in case you have any questions.
by twakefield 10y ago
Hey HN, we (gravitational) are pretty excited about this release. We'll be monitoring the thread in case you have any questions.
- atonse 10y agoHi twakefield, congrats on the release! So does this seem like a typical use in an AWS VPC: - SSH bastion server with public IP with security groups for each user - Every other server only has private IPs, only allowing access between each other and then the bastion server How do you generate and store keys? Are you using something like Hashicorp's Vault?
- russjones 10y agoHi atonse, Russell from Gravitational here. As far as configuring your VPC having the bastion (Proxy) as the only server with a public address is reasonable. One of the nice things about Teleport is that the Teleport Proxy itself doesn't have access to much, so exposing it to the Internet is fine. The Auth Server is the one that holds sensitive information and we recommend you create a security group for it and only allow it to be accessed from Teleport Proxies or Teleport Nodes. With respect to keys, they are stored and accessed via the Auth Server in Teleport. We recommend you have strong access controls on the Auth Server. If you are using the default backend (BoltDB) or directory based backend that's all you need to do. If you are using etcd we recommend you have strong access controls on the server that runs etcd as well as etcd itself, we have an example in our Teleport repo for etcd configuration if you're interested[1]. If you are using DynamoDB, we recommend having a strong IAM policy. We are not using Vault at the moment. [1] https://github.com/gravitational/teleport/tree/master/examples/etcd https://github.com/gravitational/teleport/tree/master/exampl...
- old-gregg 10y agoSpeaking of Vault, AFAIK the community expressed a lot of interest in providing custom secret storage plugins, so the latest releases have had a much simpler storage interface to implement, which is how DynamoDB was added, someone just sent a PR: https://github.com/gravitational/teleport/tree/master/lib/backend/dynamo https://github.com/gravitational/teleport/tree/master/lib/ba...
- atonse 10y agoGreat, thanks for the info!
- walrus01 10y ago> Teleport Proxy itself doesn't have access to much, so exposing it to the Internet is fine. yeah this is a bad idea in general. If you have critical stuff you need to SSH into from the public internet, keep it all in private IP space and have an openvpn gateway (or IPSEC VPN) with a public interface, and a private interface facing inwards towards the hosts. you should not even be able to route to the IP of the thing you want to SSH to unless you've authenticated to the VPN and your client device has been handed out an IP in your RFC1918 IP space. a machine like an openvpn gateway can also serve the purpose of getting you access into an OOB network (example: a public facing IP on a 100Mbps DIA circuit you've bought from a totally diverse ISP in the same colo, with a static /30), which has access into internal IP space devices such as serial console servers and ssh bastion hosts. authenticate the clients by a unique public/private key pair per client device. Easy to revoke a specific device's key from the server side if needed.
- alexk 10y ago> yeah this is a bad idea in general. If you have critical stuff you need to SSH into from the public internet, keep it all in private IP space and have an openvpn gateway This is not a bad idea in general. In fact, teleport proxy implements this exact model you have just described, where only proxy is available and acts as a jump host to the set of machines available only on the private net. The only difference is that instead of open VPN gateway it uses SSH jumphost model. Teleport proxy uses OpenSSH cert auth, in addition to that teleport node also does cert auth. Not everyone needs to always set up VPN, sometimes jumphosts + cert auth are perfectly fine.
- walrus01 10y agoI encourage all of my competition to allow access to relay to critical internal things with only SSH based authentication on a bastion/proxy, and nothing else.
- alexk 10y agoThis is not how SSH jumphosts and Teleport Proxy work. With jumphost ssh client goes through the authentication and authorization twice: * first when connecting to the jumphost public ip and requesting to execute a subsystem to allow proxying to some internal IP/host Jumphost does not terminate the SSH and in fact it is MITM capabilities are very limited. * Second time authentication and authorization happens when ssh client connects to the target SSH node. This pattern is in fact quite modern and is being expanded in the beyond corp architecture. https://research.google.com/pubs/pub43231.html https://research.google.com/pubs/pub43231.html It deprecates perimeter security model that you mention via VPN gateways and replaces it with on-demand end to end access via controlling gateway.
- qmarchi 10y agoWhat's Enterprise pricing look like for a small deployment? <10 systems
- twakefield 10y agoqmarchi - we have some different options that are dependent on support needed. If you fill out the contact form on gravitational.com I can go into more detail. Or email info@.
- canadaduane 10y agoWhen I see "contact us" as a pricing model, I mentally note that this is likely a "we charge as much as we can, depending on who you are" model. I know that's probably not what you intend. If you could give some general parameters on price, it would help me avoid that association with companies that do this.
- iamacynic 10y agoi'll save you both some time. "contact us" means at least $10k. if you don't want to spend $10k, they probably don't want you as a customer either.
- kordless 10y agoThis is a completely irrational thing to say (and is speaking for others) when you really have no idea what the facts of the matter are one way or the other.
- dexterdog 10y agoWell, he is a cynic.
- damm 10y agoIt's completely honest. When I tried to get an Elasticsearch license (when it was cheaper) sales refused to respond to my emails for a bit. Bugging someone on irc I finally got someone to respond and got a nice trial license but they /REFUSED/ to take my money. I would have dropped the money in their pocket if they would have responded. But I wasn't asking for a license for a company but for myself... so they got stupid
- nikolay 10y agoAny CloudFormation template to launch this on AWS?
- russjones 10y agoHi nikolay, we don't have a CloudFormation template, but we do have a containerized version of Teleport that is fully configured with multiple clusters that you can use to test with. https://github.com/gravitational/teleport/tree/master/docker https://github.com/gravitational/teleport/tree/master/docker