3 ms·
Agreed on this. AWS Client VPN is a decent (though admittedly a little more pricey) option: https://aws.amazon.com/vpn/pricing/ https://aws.amazon.com/vpn/prici
by brodouevencode 6y ago
Agreed on this. AWS Client VPN is a decent (though admittedly a little more pricey) option: https://aws.amazon.com/vpn/pricing/ https://aws.amazon.com/vpn/pricing/. But then again you're paying for the managed service.
- oneplane 6y agoYeah, the managed part does add to the cost (understandably) but if the half-managed approach of appliances works for you I think OpenVPN-AS is an option as well. Some people are using wireguard containers on Fargate to do the same thing.
- rrrix1 6y agoDo you happen to have a solid link / reference / GitHub repo for Wireguard on Fargate? That's exactly what I'm looking for! OpenVPN is a hot mess, but is currently the most supported mechanism across platforms. Background: I want to give my (100% global remote) development team network access to our AWS dev environment Aurora Postgresql, EFS / NFS, redis, microservices, etc. We already have a local env with docker-compose but need to debug and test in the shared cloud dev environment.
- brodouevencode 6y agoAlso interested in this approach
- vageli 6y agoI looked into this some time ago and found that wireguard cannot run on fargate due to requiring kernel modifications and the userspace implementation[0] has similar blockers. [0]: https://github.com/aws/containers-roadmap/issues/239 https://github.com/aws/containers-roadmap/issues/239
- oneplane 6y agoSadly, no. A lot of the available 'nice' containers require host access that isn't available on Fargate. The ones people tend to use on Fargate are pure user-space versions that don't work as well as others. We have evaluated a bunch of finds from blogs and public repositories but they all lack one way or another. Most of our setups use OpenVPN via OpnSense on AWS, second most popular option is OpenVPN-AS with a paid license, third is AWS OpenVPN, because of the price tag. A few test setups rely on a small EC2 instance per group (t3.small for example) with a single container and it's a bit quirky to automate, especially on large user groups. This is our main issue with WG in production so far: while the technology seems totally fine, it's not at a point where you can smoothly roll out a 'service' and get going, there are too many hoops to jump through and too many duct-tape constructions to make it integrate. (somewhat ironic, considering OpenVPN)