3 ms·
Yeah, I've largely avoided using Tower for this reason, but you could theoretically get it up to an equivalent or at least comparable security level simply by S
by rightos 9y ago
Yeah, I've largely avoided using Tower for this reason, but you could theoretically get it up to an equivalent or at least comparable security level simply by SSH tunneling it or putting it behind a good VPN. Host compromise is still a risk even with ssh.
- jdc0589 9y agoa tunnel does not protect against any of that. OP was already assuming it wasn't publicly accessible, or at least was ACLd to your company's public IPs.
- rightos 9y ago> Instead of a locked-down server exposing a public key-only SSH port, you suddenly have a whole web application stack in there. There's no webapp stack to attack if you're only able to access it via a tunnel. If you're assuming the machine you're tunneling it to is compromised, there are bigger issues at play - ones that would compromise even a plain ssh link. I'm talking a direct tunnel from your ansible master to the host you're planning to use it on, not say, into your company's network at large.