9 ms·
Hello HN! I'm the founder of HashiCorp. I'm excited to see Boundary here! I want to note a few things about Boundary, why we made it, why it is different than
by mitchellh 6y ago
Hello HN! I'm the founder of HashiCorp.
I'm excited to see Boundary here! I want to note a few things about Boundary, why we made it, why it is different than other solutions in the space, etc.
* Boundary is free and open source. Similar to when we built Vault, we feel like the solution-space for identity-based security is too commercialized. We want to provide access to this type of security to a broader set of people because we feel it's the right way to think about access control. Note: of course as as a company we plan on commercializing Boundary at some point, but we'll do this similarly to Vault, the major featureset of Boundary will remain free and open source forever.
* Dynamic resource catalogs. Other tools in this space usually require manually maintaining a catalog of servers, databases, applications, etc. We're integrating Boundary closely with Terraform, AWS/GCP/Azure, Kubernetes, etc. to give you live auto-updating catalogs based on tags. (Note: this feature is coming in 0.2, and not in this initial release, but is well planned at this point)
* Dynamic credentials. Existing tools often require static credentials. Boundary 0.1 uses static credentials, too, but we're already working on integrating Boundary with Vault and other systems to provide full end-to-end dynamic credentials. You authenticate with your identity, and instead of reusing the same credentials on the backend, we pull dynamic per-session credentials.
And more! Remember this is a 0.1 release. We have a lot of vision and roadmap laid out for this project and we are hard at work on that now. We're really excited about what's to come here.
Specifically, as a 0.1, Boundary focuses in on layer 3 connections (TCP) with minimal layer 7 awareness for protocols such as SSH. This will be expanded dramatically to support multiple DB protocols, Microsoft Remote Desktop, and more.
Also, we're releasing another new product tomorrow that is more developer-focused, if security is not your cup of tea. Stay tuned.
The Boundary team and I will be around the comments to answer any questions.
- lstamour 6y agoGiven dynamic resource catalogs and dynamic credentials, any plans to integrate dynamic policy engines, such as Open Policy Agent? https://www.openpolicyagent.org https://www.openpolicyagent.org
- mitchellh 6y agoYep. This is a little bit further out on the roadmap but yes, we plan on integrating dynamic policy engines.
- jolux 6y agoI hope this isn’t too big of a question but what do you see as the migration path towards these newer “zero trust” access control technologies for organizations that are all in on VPNs and are in a hybrid cloud position?
- jefferai 6y agoAs you say, it's a big question. But one way to start is by integrating this _within your VPN_ such that network access + credentials alone are not enough. With Boundary you could do this by setting up firewalls on the end hosts to only allow ingress from Boundary worker nodes. Eventually you can migrate towards Boundary nodes (or similar technologies) being the public ingress instead of a VPN endpoint. (Edit: clarified that I meant firewalls on the end hosts, not on the VPN or elsewhere in the network.)
- candiddevmike 6y ago> * Boundary is free and open source. Similar to when we built Vault, we feel like the solution-space for identity-based security is too commercialized. We want to provide access to this type of security to a broader set of people because we feel it's the right way to think about access control. Note: of course as as a company we plan on commercializing Boundary at some point, but we'll do this similarly to Vault, the major featureset of Boundary will remain free and open source forever. I hate this corporate speak. You're breaking into the space by giving away (basic, as you will commercialize any advanced) features under the guise of open source altruism. The products HashiCorp sells are open core, and you should be more honest about it (GitLab is!). I wish you operated more like other, real, open source companies that use subscriptions or managed service offerings and don't lock features behind various obscure pricing tiers. This is Shareware 2.0. The difference between what HashiCorp does and what a real open source company like Rancher does is stark: HashiCorp has products, Rancher builds communities. Contributors to HashiCorps stuff have to play in a very specific sandbox, lest they implement lucrative features. Contributors to Rancher help the community at large and have full visibility into the codebase, empowering them to fix or add functionality without restrictions.
- nexuist 6y agoHow is this corporate speak? If an indie dev said his/her project is going to be open source initially and then newer features would get monetized, would your first thought be that this dev is "breaking into the space under the guise of open source altruism"?
- a1369209993 6y agoIf they started out by misleadingly[0] describing it as "$THING is free and open source."? Yes! Edit: 0: It's (presumably) technically not false now, but the implication is that $THING is honestly intended to be FOSS, immediately followed by admiting that their actual intent is to sabotage that embrace-extend-extinguish-style as soon as it's commercially expedient to do so.
- 6y ago
- A_No_Name_Mouse 6y agoIs there a simple paper that explains how this works on a technical level? I have a hard time visualizing how a connection to a remote host would be set up if it runs through Boundary. Does "without requiring direct network access" mean Boundary works as a proxy? And how does Boundary enable the connection if the host does not have direct network access?
- armon 6y agoWe don't have a white paper on this yet, but we have a white board video that explains both how it works conceptually as well as at a more technical level of deployment architecture and data flow. https://www.youtube.com/watch?v=tUMe7EsXYBQ&feature=emb_title https://www.youtube.com/watch?v=tUMe7EsXYBQ&feature=emb_titl...
- A_No_Name_Mouse 6y agoWonderful video, really clear!
- emddudley 6y agoThis is a really nice video. I appreciate the patient walkthrough of the concepts and motivation.
- atonse 6y agoArmon, just wanted to say your whiteboard videos are excellent. And the clarity of thought demonstrated in them over the years has been a great ad for the products too. The low tech aspect also feels more human. But I had a chuckle at the idea of you wheeling a whiteboard into your house (if that is where it is filmed).
- jefferai 6y agoBy "direct network access" we mean between the client and the end host. The Boundary worker node (which proxies traffic) would need to be able to make a network connection to the end host, and the client in turn would need to be able to make a network connection to the worker node. This indirection provides a way to keep your public and private (or even private and private) networks distinct to remove "being on the same network" as a sufficient credential for access. At the same time, it ensures that the traffic is only proxied if that particular session is authenticated.
- zellyn 6y agoLooks great! A couple of questions: Can you view logs of SSH sessions after the fact? Can you live-view a session? Can you require a pairing authorization like with https://github.com/square/sudo_pair https://github.com/square/sudo_pair?
- mitchellh 6y agoAll of the above is on the roadmap. Our initial focus is on making the connections easy. We have some work to do there still. We'll then move on to more management features like this. They're both super important but from an initial adoption perspective we feel the latter is moot if the former (connections) don't work easily.
- zellyn 6y agoMakes sense. You should integrate TailScale too, so you don't need to shunt traffic through the boundary nodes
- tinco 6y agoWould it not be easier to replace SSH with something more modern that actually exposes that as a feature? I've been thinking about that the past couple of years, with today's building blocks an SSH alternative is so easy to build. I bet if you guys were to build or back such a system it would be the right quality and get the adoption it needs. Opaque SSH sessions are such a thorn in my side.
- time0ut 6y agoDo you think there will be any synergy or potential interaction with consul connect at some point?
- mitchellh 6y agoAbsolutely, 100%. This is already well discussed internally. :)
- cratermoon 6y agoOver in another thread this was compared to Google's BeyondCorp. Can you comment and compare/contrast Boundary with the concepts of BeyondCorp?
- mitchellh 6y agoBoundary can be viewed as an implementation of some of these ideas!
- LinuxBender 6y agoDo you have a video showing a demo of managing a fleet of servers? Does this also address machine-to-machine ssh key trusts? Do you have a contrib repo with existing ansible, chef, puppet scripts to build your cluster and also for deploying agents to machines?
- dabeeeenster 6y agoLooks interesting! Couple of things: 1. It's not clear to me how you actually secure the targets? Do you just enable access to the IP address of the controller proxy? In the video you mention a gateway but there's no description of that in the docs? 2. Is it possible to proxy a web browser session? Or is it limited to individual requests via something like curl at the moment?
- sytse 6y agoThis is awesome, thanks for making this. Boundary seems like the missing open source building block to achieve Zero Trust. Zero Trust means authenticating per application instead of per network. For more context see https://about.gitlab.com/blog/2019/04/01/evolution-of-zero-trust/ https://about.gitlab.com/blog/2019/04/01/evolution-of-zero-t... Proxying connections as Boundary does seems like the most elegant solution to achieve this in a way that doesn't require modifying the application.
- mike-cardwell 6y agoArgh. I already find it a nightmare to figure out how to combine hashicorp tools together. Now there's one more! ;) E.g, if I want a Consul backed Vault, whilst using Vault to generate TLS certs or other creds for Consul. Especially if I want to run either/both of those services using Nomad, backed by Consul. Hopefully I wont have the option of authenticating against any of these services using Boundary. Especially if Boundary is backed by Consul.
- mrweasel 6y agoMaybe you’re not using Terraform. I suspect that your problem is an insufficient usage of HCL.
- ETHisso2017 6y agoAll hail Hashi-stack!
- deleted 6y ago[deleted]
- mitchellh 6y agoIndeed. Our recommendation with Vault now is to use the built-in storage[1] to break that dependency. If you must use Consul, we recommend separate clusters. One way we're simplifying this a lot for people is the introduction of our managed services[2][3]. We understand not everyone can use a managed service though! Boundary will integrate fairly deeply with Consul/Vault but these integrations will be optional. [1]: https://www.vaultproject.io/docs/configuration/storage/raft https://www.vaultproject.io/docs/configuration/storage/raft [2]: https://www.hashicorp.com/blog/hcp-consul-public-beta https://www.hashicorp.com/blog/hcp-consul-public-beta [3]: https://www.hashicorp.com/blog/vault-on-the-hashicorp-cloud-platform https://www.hashicorp.com/blog/vault-on-the-hashicorp-cloud-...
- mike-cardwell 6y agoThanks for the response. My comment was half in jest, but it has been a pain point for me.
- NovemberWhiskey 6y agoHi Mitchell: what's your competitive landscape with Boundary? When I first looked at the product description, I thought I might be looking at a "zero-trust identity-aware-proxy" sort of thing, but as I read more I got more of the "privileged access management" vibe with more of a focus on controlling access to infrastructure for developers vs. applications for end users.
- newman314 6y agoSo I've been casually doing some research into this in the past and was just updating my list so here's what I have so far. If I have missed any, please let me know. * Azure App Proxy * Google IAP * Amazon WorkLink * Cloudflare Access * Zscaler Private Access * Duo Beyond * Hashicorp Beyond
- all_usernames 6y agoGoogle BeyondCorp?
- fairramone 6y agoI think BeyondCorp == IAP
- theptip 6y agoIAP is Google’s concrete implementation/product, BeyondCorp is the overall philosophy (not a product)
- deleted 6y ago[deleted]
- hossi 6y ago* PrivX by SSH.COM We provide a lean PAM solution for multi-cloud infrastructure access.
- nielsole 6y ago* Teleport https://gravitational.com/teleport/ https://gravitational.com/teleport/
- jcims 6y agoThinking of this as a means for privileged access management, would it be possible for Boundary to gather artifacts (e.g. keystroke logs and/or screen shots) from the session? This might trigger some folks but have you explored any options for delivering some or all of the Boundary infrastructure through serverless/faas?
- mitchellh 6y agoYes this is on the roadmap!
- lifty 6y agoHey Mitchell, congrats on the new announcements, great stuff! Out of curiosity, how are you building and operate HCP? Are you running it on top of Kubernetes or Nomad, or you're doing some other custom stuff?
- mitchellh 6y ago- Full HashiCorp stack (Nomad, Consul, Vault, Terraform) - Cadence (https://temporal.io/) - Microservice architecture over gRPC and Consul Connect - All services written in Go - Customer clusters are created/managed by programmatically running Terraform using just-in-time cloud credentials from Vault - All internal TLS certs for customer clusters dynamically created using Vault - All external TLS certs for customer clusters dynamically created using LetsEncrypt via Terraform - Frontend is Ember
- digitallogic 6y ago> Customer clusters are created/managed by programmatically running Terraform I have soooo many questions about best practices doing this. I run a service that needs to dynamically provision AWS resources, and lacking a clear path to do this programmatically, I shell out to Terraform. * I assume you aren't shelling out :). Do you have any additional helper libraries on top of the Terraform code base to make it more of a a programmatically consumable API, as apposed to an end user application? * Are you still pointing at a directory with resources defined in HCL, or are the resources defined programmatically? * What are you using for state storage? * What is the execution environment for the programmatic Terraform process? Since Terraform uses external processes for plugins, I've hit some issues with resource constraints around the max number of process sysctl's in containerized environment where I have multiple Terraform processes running in the same container. edit: formatting
- mitchellh 6y agoYeah this isn't very easy to get right at the moment so there is not going to be any silver bullet here. We had to iterate on our runner a lot to get this right, but we have a lot of experience since we do this for Terraform Cloud too. Answering your questions: > * I assume you aren't shelling out :). Do you have any additional helper libraries on top of the Terraform code base to make it more of a a programmatically consumable API, as apposed to an end user application? We in fact are. There are lots of security concerns you have to consider with this. We published a library to make this easier: https://github.com/hashicorp/terraform-exec https://github.com/hashicorp/terraform-exec > * Are you still pointing at a directory with resources defined in HCL, or are the resources defined programmatically? HCL mixed with the JSON flavor of HCL for programmatically generated stuff. Variables in JSON format also programmatically generated. > * What are you using for state storage? We output it to a file and handle this in an HCP microservice. We encrypt it using the customer-specific key with Vault and store it in a bucket that only the customer-specific credential has access to. If there is an RCE exploit somehow in our workflows, they can only access that customer's metadata. > * What is the execution environment for the programmatic Terraform process? Since Terraform uses external processes for plugins, I've hit some issues with resource constraints around the max number of process sysctl's in containerized environment where I have multiple Terraform processes running in the same container. Containers in HCP and VMs in Terraform Cloud due to increased isolation requirements. HCP has less strict requirements because the Terraform configs and inputs are more tightly controlled.
- TheGuyWhoCodes 6y agoAre there any plans or a way to use existing tools? By existing tools I mean winscp or any other tools that use a normal ssh client? RDP etc. I guess for shh and rdp you can just run the Boundary cli with a the predefined target in a terminal embedded into the UI (MremoteNG, MobaXterm etc) but tools like winscp are very much used for sftp file transfers. A desktop client with a list of services/targets would also be great. Especially for the less technologically inclined individuals. I know that people have their own opinions on port knocking but I find it as a good tool to remove a lot of noise, some pre built tool for that would be nice but could always just use fwknop-2
- mitchellh 6y agoYou can do this already, The `boundary connect ssh` stuff is just a convenience. You can spin up a local boundary proxy to anything and just connect anything that speaks TCP over it. This allows you to use all the tools you just named. A desktop client is on the way, we already have an internal build of parts of it but it requires more work and didn't make it for 0.1.
- TheGuyWhoCodes 6y agoThanks for answering. boundary proxy is an ok step but user experience should be streamlined especially if it's for teams and orgs and not just individuals who want to hack scripts but I full understand it's a 0.1 release. Another thing I couldn't find in the docs is support for multiple installations, let's say I have different vpcs (In different accounts) or I have one on-prem installation and one in a cloud how do I login/switch/configure the cli to work seamlessly with multiple controllers.
- jefferai 6y agoWe don't have something natively, but you can control the address via BOUNDARY_ADDR env var or the -addr flag per-call, and you can use -token-name with the CLI to switch between named tokens, which can be sourced from different accounts. Together it'd be pretty easy to write a shell alias to do what you're looking for.
- talawahtech 6y agoWhat is used to secure/encrypt the connection between the clients and the workers? I did a quick search in the GitHub repo for WireGuard and didn't get any results so I guess you aren't using it.
- jefferai 6y agoCheck out https://www.boundaryproject.io/docs/concepts/security/connections-tls https://www.boundaryproject.io/docs/concepts/security/connec... for lots of details!
- talawahtech 6y agoThanks! That is exactly what I was looking for.
- carlosf 6y agoHappy Nomad + Consul + Terraform user here. Thanks a lot for the great products, but please give us managed Nomad already. Or even better: a Heroku like app platform. I want to give you money, but I really dislike your companies' enterprise offerings. BTW I believe there's a great opportunity for Hashicorp right now. Cloud providers are good at selling building blocks, but are terrible at selling a vision of how you should build your applications. On the other hand, low code / enterprise application platforms are a disgrace as always. IMO a coherent stack of managed Nomad + Consul + Vault could provide a solid middle ground for those who want to build apps without the burden of managing K8s or navigating through the incomprehensible maze of products offered by public clouds.
- mitchellh 6y agoHello! Thank you :) (1) HCP Nomad is coming. We announced HCP Consul public beta and HCP Vault private beta today (on AWS, more clouds later). HCP Nomad is planned but not quite ready to talk about beyond that yet. That is "managed Nomad." (2) Re: Heroku-like app platform. Watch tomorrow's keynote or catch up on our announcements tomorrow. It isn't this, but I think it'll give you an idea of the vision we're heading towards and that is relevant to this idea.
- ksec 6y ago>Or even better: a Heroku like app platform. So Hashiku? :) Seriously Heroku seems to have stopped innovating. I wonder how much is Heroku worth now.
- 3np 6y agoFrom a first look this is really exciting. And cool to see you here on HN! I live your positioning and how you’re first and foremost building FOSS software and tools that you leverage on, as opposed to building a commercial offering that you then release software for. It’s a vital distinction that sets you apart from eg Google. Let’s say you have an org that’s doing the whole Consul/Nomad/Vault thing, and starting to have their Nomad jobs using Consul Connect (and it’s proxies/gateways for external).. that’s already a proxy sidecar used for all service ports. How does Boundary fit here? Is it put before/after Connect, is the plan to integrate them, or are they supposed to not be used together?
- jefferai 6y agoIn an immediate sense you could have targets point to services handled by Connect, so you'd have client -> Boundary worker -> local Connect entrypoint -> end service. We'll be looking more closely at other integration possibilities going forward!
- traceroute66 6y agomitchellh I'm sorry, but please cut the corporate-speak. Reality is that your statements are different from your actions. "similarly to Vault, the major featureset of Boundary will remain free" Sounds great doesn't it. Except Hashicorp decide to hide Multi-factor authentication in Vault behind the paywall. I mean, I'll forgive you putting a lot of the Vault features behind the paywall (e.g. replication). But for a security product. Putting a core component of 21st century security (MFA) behind the paywall ? Pretty unforgivable.