6 ms·
Unless you're behind a load balancer which terminates TLS and the traffic you deal with is purely http.
by sofaofthedamned 7y ago
Unless you're behind a load balancer which terminates TLS and the traffic you deal with is purely http.
- briffle 7y agosure, as long as you don't connect to ANY outside url's for anything
- aflag 7y agoWhich you probably shouldn't be doing for most of your services anyway.
- icebraining 7y agoI don't remember the last project I did which didn't have some sort of integration with an external service. I guess if you use microservices, most components won't need it; I mostly use monoliths.
- aflag 7y agoI guess if everything is in a single service you're bound to have some sort of outbound connection at some point. Although, in my experience, you can go very far within your vpc.
- alanwreath 7y agoI wonder if this would be important with service mesh and mutual tls...
- jacques_chester 7y agoService meshes make in-cluster mTLS a more-or-less automatic feature, which is worth having. Some will terminate TLS at ingress and convert to mTLS internally. The argument above is that you shouldn't do this and should instead plumb that ingressing TLS traffic all the way to the container. The downside of plumbing directly to the container is that you lose many of the routing features of a service mesh. If it can't inspect the traffic, it can't do layer 7 routing. It can only route and shape at layer 4.
- mark242 7y agoPlease don't do this anymore. End-to-end encryption is extremely easy to set up and maintain. P2PE will absolutely lull you into a false sense of security.
- sofaofthedamned 7y agoEh, don't teach my about the systems I run. I'd love to run TLS end to end but in this one? Nah, not worth it.
- baq 7y agoI work at $CORP. I don't trust my enterprise IT department with unencrypted traffic for fear of falling victim to stupid traffic shaping or deep packet inspection intrusion prevention going haywire.
- sofaofthedamned 7y agoGood for you. In my current gig the trade-off is different. I don't work for Google.
- arcticbull 7y ago"Don't teach me about ..." -- aren't we all here to learn? Let's keep the tone civil and assume the best.
- solatic 7y agoLast time I checked, mTLS incurred significant performance penalties and required significant soak testing to ensure that performance would be acceptable for a given application. If you're a small company, you have much lower hanging fruit to chase.
- jacques_chester 7y agoIn my understanding there's additional overhead at handshake, but after that the performance is basically identical. The client certificate mostly acts to identify the client to the server, but otherwise the business of picking session keys etc is the same. At this point TLS overhead is close to free. I think the start of this thread was a plea not to terminate HTTPS at the edge, but instead to plumb it all the way to the serving container. That's unlikely to be mTLS in any case.
- mschuster91 7y ago> and the traffic you deal with is purely http. Which is a truly rare case as many backend APIs these days are mandatory secured by HTTPS (or LDAPS, SMTPS, IMAPS to name a couple other openssl-based secure protocols).
- Gladdyu 7y agohttps://amp.businessinsider.com/images/5271388a6bb3f7ac4756d90c-480-360.jpg https://amp.businessinsider.com/images/5271388a6bb3f7ac4756d...
- deleted 7y ago[deleted]
- Thaxll 7y agoThis has nothing to do with being a LB, if you need to do outgoing calls with https you most likely need ca-certificates.