4 ms·
I'm currently looking into implementing a VPN setup on AWS to allow my team to access services in private subnets. Tailscale seems great but too pricey for our
by probotect0r 5y ago
I'm currently looking into implementing a VPN setup on AWS to allow my team to access services in private subnets. Tailscale seems great but too pricey for our small company. I'm playing with Pritunl now, but looking for other suggestions. Ideally I want to have some SSO functionality so we don't have to manage users and the team can log in with their company Google account. Any suggestions for this type of setup?
- whalesalad 5y agoWireGuard. Run it on a bastion box. There isn’t a batteries included tool I know that’s good at this. The WireGuard ecosystem means you gotta glue a lot of OSS stuff together. tldr make sure the bastion box can reach the stuff you need it to reach as far as subnets and security groups go, ensure kernel will fwd traffic from WireGuard clients, run WireGuard daemon, and expose it to the outside world via eip. I’m oversimplifying (dns, sec groups, routing client traffic to other subnets) - but hopefully that explains the gist. I have a small Python script that takes a XLSX file as input and populates a dir with config files and QR code images for each user. Or you can check out some of the OSS ways to do self-service vpn mgmt with a web UI that authenticates against Google auth. I haven’t deployed this yet but it looks cool https://github.com/subspacecloud/subspace https://github.com/subspacecloud/subspace If you know this sort of tech well it is not hard to deploy and manage yourself. But tailscale has a really killer clientside experience and “just works” so honestly it might be worth the $$$
- probotect0r 5y agoThanks for the suggestion. I have seen subspace, but haven't had a chance to explore it deeply. I don't mind deploying and managing my own setup, but since my team is small, I want to limit how much time I have to spend on this in the long run. I have definitely considered running my own setup of barebones WireGuard, but haven't come across an elegant user management solution.
- alephu5 5y agoWireguard isn't so good for mesh networks because every new node requires reconfiguring all the others. Even with management utilities this is a pain, so instead I recommend something like nebula https://github.com/slackhq/nebula https://github.com/slackhq/nebula
- 3np 5y agoNot necessarily. You can have one or several (potentially load-balances) “gateways” which act as entrypoints into subnets. At some point you’ll probably want to integrate with some identity management , but dozens of users and hundreds of servers are totally fine to manage as yaml in ansible IME.
- deleted 5y ago[deleted]
- jeroenhd 5y agoI've looked into replacing my personal WireGuard setup with an innernet [0] managed network. You can throw it onto a generic VPS and make managing WireGuard peers super easy. It's not unlike Tailscale and nebula (that others already mentioned) but I think it deserves to be mentioned. [0]: https://github.com/tonarino/innernet https://github.com/tonarino/innernet
- redninja83 5y agoAs other have suggested, Nebula (https://github.com/slackhq/nebula https://github.com/slackhq/nebula) is pretty elegant. It has groups-based access built in which is extremely convenient. You can bolt-on SSO fairly easily - just create a certificate signing service. I created https://github.com/unreality/nebula-mesh-admin https://github.com/unreality/nebula-mesh-admin in a weekend, so its fairly easy to add a SSO flow in.
- probotect0r 5y agoThanks! This seems pretty interesting, I will definitely explore it further.
- turtlebits 5y agoAWS SSM allows you to remote as well tunnel to hosts regardless of subnet.
- probotect0r 5y agoYeah, we do use it for ssh access. I know about the portforwarding capabilities, but haven't explored it for this use case. Given that our environment is dynamic, I don't know if accessing internal services via portforwarding over ssh is going to be feasible.