15 ms·
HashiCorp Boundary
- jolux 6y agoSeems like the BeyondCorp-ish “zero trust” remote access space is heating up. This looks similar in some ways to Cloudflare One which was announced Monday: https://blog.cloudflare.com/introducing-cloudflare-one/ https://blog.cloudflare.com/introducing-cloudflare-one/
- basch 6y agoIt's already pretty crowded. https://telegra.ph/ZeroTrust-Vendors-04-23 https://telegra.ph/ZeroTrust-Vendors-04-23 Expect consolidation. That or it becomes a commodity expectation of any other purchase, and not a selling point.
- jolux 6y agoI’m expecting both. Probably a standard AWS/IAM feature eventually.
- lizhang 6y agoI'm guessing the Cloudflare One announcement forced Hashicorp to announce this so they wouldn't lose a lot of potential customers due to vendor lock-in.
- cavisne 6y agoNot surprising when corporate VPNs have gone from a handful of the company working from home to the entire company working from home.
- warkdarrior 6y agoThis looks like an authenticated proxy. I assume you would need to locally reconfigure your clients (ssh, browser, whatever) to use the Boundary server as a proxy.
- parliament32 6y agoOther way around, boundary needs to exec your client application. They're more clear about how it works here: https://www.boundaryproject.io/docs/getting-started/connect-to-target https://www.boundaryproject.io/docs/getting-started/connect-... Boundary comes with built-in wrappers for ssh, rdp, and postgres, but you can "boundary exec" to run some other application inside the TCP-wrapped transport, apparently.
- zokier 6y agoSome sort of LD_PRELOAD style trickery? Or are they intercepting syscalls? edit: seems nothing that complicated, more like ssh-style tunnel where Boundary has a local listening socket which you need to point the client to. That is if I'm understanding it correctly.
- armon 6y agoThat is correct! The local proxy has a listening socket and handles all the authentication, encapsulation, and forwarding transparently.
- parliament32 6y agoSo does it intercept all connections on that port (from the client app) and pass them along? Or do I need to reconfigure my client application to talk to localhost:whatever? Your only example is that curl using a hostname, it's not really clear.
- bluu00 6y agohttps://web.archive.org/web/20201014160020/https://www.hashicorp.com/blog/hashicorp-boundary https://web.archive.org/web/20201014160020/https://www.hashi... link wasn't working for me, so.
- marmaduke 6y agoThis looks like an interesting alternative to k8s ingress, even if the goal is similar, especially when the default ingress controllers don't support e.g. SSH. Way too much ceremony for scientific compute sites tho
- t3rabytes 6y ago> When a user establishes a TCP session through Boundary, a Boundary worker node seamlessly proxies the connection. Boundary sounds like the perfect mash-up of Google's bastion-less SSH access to GCE instances and actual IAM. Exciting!
- latentpot 6y agoIs this very similar to cyberark, but without the logging and recording of usage?
- yegle 6y agoLooks like Google's BeyondCorp: https://cloud.google.com/beyondcorp https://cloud.google.com/beyondcorp. If you are on GCP, you can already use it https://cloud.google.com/iap https://cloud.google.com/iap to protect your HTTP and TCP backend. This is not something new. The earliest open source project that I can recall is https://github.com/bitly/oauth2_proxy https://github.com/bitly/oauth2_proxy (albeit it might be missing the part where proxy passing identity to the backend). Pomerium is another open source project that's actively maintained. I've been using it as a reverse proxy to all my homelab websites (grafana, miniflux etc). I can now safely access all of these internal resources from outside of my home WiFi with automated SSL certificate configuration and renewal. You can theoretically protect your SSH connection via these IAP proxies, using the Chrome SSH extension and open source SSH relay implementation like https://github.com/zyclonite/nassh-relay https://github.com/zyclonite/nassh-relay (but I personally haven't tried that). Disclaimer: I work for Google and am a casual contributor to the Pomerium project.
- windexh8er 6y agoAlso looks very much like Gravitational Teleport [0], which has been amazing to use. Teleport has a lot of advantages over Boundary right now based on it's architecture. But Hashi does a good job of iterating quickly, so I'd guess as with most of their products, it evolves quickly. [0] https://gravitational.com/teleport/ https://gravitational.com/teleport/ Disclaimer: I have no affiliation with any of these companies.
- res0nat0r 6y agoAlso similar to Cloudflare One which was just announced: https://blog.cloudflare.com/introducing-cloudflare-one/ https://blog.cloudflare.com/introducing-cloudflare-one/ I think moving away from VPN's is gaining more adoption and a good thing overall.
- francislavoie 6y agoLooks like RBAC and SSO are paid features with Teleport (but I may be misunderstanding)
- throwaway873993 6y agoI'd rather use https://userify.com/ https://userify.com/
- mitchellh 6y agoHello HN! I'm the founder of HashiCorp. I'm excited to see Boundary here! I want to note a few things about Boundary, why we made it, why it is different than other solutions in the space, etc. * Boundary is free and open source. Similar to when we built Vault, we feel like the solution-space for identity-based security is too commercialized. We want to provide access to this type of security to a broader set of people because we feel it's the right way to think about access control. Note: of course as as a company we plan on commercializing Boundary at some point, but we'll do this similarly to Vault, the major featureset of Boundary will remain free and open source forever. * Dynamic resource catalogs. Other tools in this space usually require manually maintaining a catalog of servers, databases, applications, etc. We're integrating Boundary closely with Terraform, AWS/GCP/Azure, Kubernetes, etc. to give you live auto-updating catalogs based on tags. (Note: this feature is coming in 0.2, and not in this initial release, but is well planned at this point) * Dynamic credentials. Existing tools often require static credentials. Boundary 0.1 uses static credentials, too, but we're already working on integrating Boundary with Vault and other systems to provide full end-to-end dynamic credentials. You authenticate with your identity, and instead of reusing the same credentials on the backend, we pull dynamic per-session credentials. And more! Remember this is a 0.1 release. We have a lot of vision and roadmap laid out for this project and we are hard at work on that now. We're really excited about what's to come here. Specifically, as a 0.1, Boundary focuses in on layer 3 connections (TCP) with minimal layer 7 awareness for protocols such as SSH. This will be expanded dramatically to support multiple DB protocols, Microsoft Remote Desktop, and more. Also, we're releasing another new product tomorrow that is more developer-focused, if security is not your cup of tea. Stay tuned. The Boundary team and I will be around the comments to answer any questions.
- lstamour 6y agoGiven dynamic resource catalogs and dynamic credentials, any plans to integrate dynamic policy engines, such as Open Policy Agent? https://www.openpolicyagent.org https://www.openpolicyagent.org
- mitchellh 6y agoYep. This is a little bit further out on the roadmap but yes, we plan on integrating dynamic policy engines.
- GNOMES 6y agoInteresting, seems similar to Cloudflare One that was announced the other day. https://news.ycombinator.com/item?id=24753940 https://news.ycombinator.com/item?id=24753940
- wyck 6y agoWith a name like HashiCorp I expected this to be a decentralized blockchain identity network similar to IBM's Sovrin, still really cool though, managing id's and permissions is such a pita.
- wmf 6y agoHashiCorp predates most of the blockchain hype; it's named after founder Mitchell Hashimoto.
- outworlder 6y agoHashicorp is behind Terraform, Vault, Consul, Nomad. Surely you have heard of at least one of those?
- candiddevmike 6y agoIt looks like you still have to manage users on the hosts for PAM, including SSH keys (or use Vault I suppose). It's too bad that this can't perform all of that functionality--setup a server, install a boundary client, and manage all of the PAM things through Boundary.
- malnick 6y agoWe plan on integrating with Vault to perform transparent credentials injection in the not so to distant future. This is a 0.1 product after all, and we still have a lot to build!
- cbb330 6y agoThere are a few comparisons being introduced already in this thread, and I'm tempted to ask of more, so I'd love to see documentation on this vs. other solutions like is presented with Terraform: https://www.terraform.io/intro/vs/index.html https://www.terraform.io/intro/vs/index.html
- hossi 6y agoSince you asked, we have a commercial zero-trust product very similar to this. As a quick comparison: In our architecture, the worker node (extender) only needs outbound direct access to contact the master node. Unlike many of our competitors, we promote the usage of ephemeral certificates instead of secrets management or minting. We support a number of identity providers and dynamic host directories. Connections can be formed either with native clients or web browser (SSH, RDP, HTTPS) with session recording for auditing purposes. Check it out here https://www.ssh.com/products/privx/ https://www.ssh.com/products/privx/
- PaulWaldman 6y agoI want to give a shout out to Tailscale. It relies on Wireguard and has been dead simple to setup and configure. Stability has been great as well.
- arcticfox 6y agoI am also a big Tailscale fan, is anyone able to do a quick comparison on how Boundary relates?
- basch 6y agoTailscale isnt a deny first, allow based on role/condition type product. Tailscale creates the equivalent of a wide open lan (it has other isolation options but that kind of control based on the identity of the person on the network, isnt its intended goal) where everyone connected can see everyone else.
- philsnow 6y agoFrom what little I know of both, Tailscale provides L2 access into a network that you might not otherwise have access and once you're in you can get anywhere from there, but Boundary hands out individual, already-connected TCP sockets directly to services running on endpoints. If you're looking for something like a VPN and you're just going to SSH over it, either would probably work for you, but while Boundary can allow users to only connect to port 22 on certain hosts, I think if you wanted to do similar with Tailscale you'd be in iptables/ufw and "tagging / authz-ing traffic with unix uids" territory.
- lifty 6y agoTailscale is based on wireguard, so only does L3.
- 0xFFFE 6y agoLooks like Yahoo's Athenz https://github.com/yahoo/athenz https://github.com/yahoo/athenz
- nokiasa1 6y agoCan anyone explain if this can be used to share a linux samba server shares? If yes, could you point me out to right direction. Thanks
- jon-wood 6y agoI’m sure it can, given at its core it just tunnels traffic from one place to another, but to be brutally honest this is a 0.1 release and if you can’t work out how to do this from the documentation you’re going to have a really bad time working out why it broke down the line.
- luminousbit 6y agoPersonally I’ve been a big fan of strongDM (https://www.strongdm.com/ https://www.strongdm.com/). Lightyears ahead of teleport or any of the other solutions out there. Built for great auditing and zero trust. Best of all it’s multi-protocol. So you can do SSH, SQL, K8s, HTTP all with one access system. Had it in prod for almost two years. Gonna be a long time before hashicorp or anyone else can catch up with the level of depth.
- pferde 6y agoStrongDM does indeed look interesting. Can it be completely self-hosted? I am asking because some of the architecture docs mentioned "app.strongdm.com" as a necessary element, which has a webpage behind a (customer?) login. This is an external dependency that is not acceptable for my use case. I haven't found a conclusive answer in their documentation yet.
- jmccarthy 6y agoJustin here, co-founder and CTO of strongDM. The policy and audit functions of our product are hosted by us, but all the sensitive data transit - the proxies themselves - are hosted by you. Hope that helps!
- pferde 6y agoThanks for the reply, I really appreciate it. Unfortunately, that is not acceptable for what I had in mind.
- outworlder 6y ago> Best of all it’s multi-protocol. So you can do SSH, SQL, K8s, HTTP all with one access system. Teleport is SSH based so you can tunnel other protocols.
- bulatz 6y agoI tried to set up sftp via strongdm hoping it will work since sftp is using ssh, but I failed. It just did not connect
- faitswulff 6y ago> With Boundary, access is based on the trusted identity of the user, rather than their network location. The user connects and authenticates to Boundary, then based on their assigned roles they can connect to available hosts, services, or cloud resources. Is this the main idea behind BeyondCorp and CloudFlare One, as well? If so this is the clearest explanation I've seen of it.
- cratermoon 6y agoIt is and it's something I noted, too.
- rodgerd 6y agoThis looks wonderful. I spend a lot of time and energy trying to keep people from breaking modern infra with 1980s IP-based security models, and this could be another tool in the arsenal to help with that.
- buzzdenver 6y agoHow does your system compare to Appgate?
- fasteo 6y agoHonest question: how is it different/better than setting up a OpenVPN server ?
- anderspitman 6y agoSearch terms "BeyondCorp" and "Zero trust" will get you started.
- scarlac 6y agoVPN clients traditionally virtualizes your network interface entirely. Everything acts as if your are actually physically present because it's virtualized nicely. It's great because it "just works". These "non-VPN" solution seem to use a client on your machine that change any DNS lookup through the OS layer by hooking into gethostaddr() and returning the same IP for all domains if they are in the list of hosts that should be virtualized. Then only the traffic to domains that are needed is virtualized, anything else is untouched. YouTube and Netflix won't get piped over your company network, as an example. Disclaimer: I don't really know that this is how it works but this is how other providers do it.
- nosequel 6y agoI think you meant to write "boundaq".
- teknopaul 6y agoThis is great, I hope where I work never implementes it :) Getting access to everything in "one hop" is mighty convenient. Especially now that one hop involves 2fa and finding my phone down the back of the sofa while production has a sev one.
- nikisweeting 6y agoAny example snippets of what the connection setup looks like on the server side? e.g. something like a docker-compose sidecar exposing an nginx container to users via boundary would really help me understand how this is supposed to be used in practice. Looking for an example like my comparison here between argo, wireguard, tailscale, letsencrypt, caddy, and ssh ingress: https://gist.github.com/pirate/1996d3ed6c5872b1b7afded250772f7c https://gist.github.com/pirate/1996d3ed6c5872b1b7afded250772...
- malnick 6y agoWhile we don't have a docker compose example (yet), I think the diagram in our reference architecture for AWS might be useful in visualizing a HA deployment and how a client connects to targets: https://github.com/hashicorp/boundary-reference-architecture https://github.com/hashicorp/boundary-reference-architecture
- mmettler 6y agoAnother company to watch here is Tailscale, which is Wireguard-based: https://tailscale.com/ https://tailscale.com/ (disclosure: small Tailscale investor)
- tonymet 6y agohow does one go about that?
- btgeekboy 6y agoI like the people behind Tailscale, but I’ve yet to figure out how they’re different than ZeroTier.
- ptman 6y agoBased on hearsay: * wireguard (faster) * easier * more stable
- TheFlyingFish 6y agoI've tried both. I ended up going with Tailscale because: - Better throughput overall. - better NAT holepunching. E.g. ZeroTier gives up entirely with "symmetric NAT" where each outbound connection gets a random source port, but Tailscale has a few extra tricks that it can try (including opening a whole bunch of outbound connections, trying ports at random, and hoping the birthday paradox will kick in, which I think is pretty cool.) - But most of all, Tailscale didn't suffer from weird intermittent throughput/latency issues between different cloud providers the way that ZeroTier did. Sometimes my machines could talk to each other pretty fast, other times it was clamped down to ~10 MB/s for no apparent reason. Sometimes it only showed up in one direction, sometimes both. I gave up on trying to troubleshoot it when I discovered Tailscale. That said, I still like ZeroTier a lot and think it's a great project. It also provides a whole LAN layer, with stuff like actual broadcast traffic, for which Tailscale has no equivalent.
- spockz 6y agoWhat is it this exactly adds on top of an authenticating reverse proxy like nginx? Is it the rbac to grant access to specific resources based on their labels instead of per hostname/servicename auth?
- clafferty 6y agoThis looks awesome, great job! One thing that will slow me down from using this is I've not settled on an ID or Access Management system. Being a small company, we occasionally need to grant system access to contractors or other dev teams. The problem is we don't want to grant the access too wide and specifying fine grained controls takes a lot of time. Armon mentions Okta and Ping, does anyone have any recommendations in this space that would work for managing a small team with occasional on/off boarding of contractors?
- sterlinm 6y agoThis looks pretty interesting both for some projects at work and for my homelab. I'm a data scientist with an amateur interest in devops so apologies if this is a silly question, but I'm trying to get a sense of the use cases. Would it make sense to use boundary as a way to manage access to web-based developer environments using an IDP for authentication (e.g. Github, Google, Okta, etc). I'm thinking of tools like JupyterLab/Hub, RStudio Server, etc. Or is that outside the intended scope of Boundary?
- jzjzjz 6y agoI'm looking for more clarification on how i can fit this into my Cloudflare ecosystem. Assuming many of your clients are consuming Cloudflare and all of their backbone, security, networking, and remote work services. Would I just have Boundary authenticate via Cloudflare Access and whatever identity provider Cloudflare One is integrated with and move to the RBAC policy phase of the authentication - is this where i am seeing that additional value from Boundary by having that additional on demand credential rotation to various internal Apps and DBs once i am past the SSO stage? CF One is more of a vertically integrated all in one service addressing all of my other networking and security needs so it's not really going anywhere. I think you guys could do well to release a Cloudflare integration paper, it might help with traction on on-boarding customers. Thanks!