4 ms·
I went with OSv (another unikernel) for a previous pet project and, while I really loved the concept, I found the tooling to be immature. This project’s tooling
by invokestatic 5y ago
I went with OSv (another unikernel) for a previous pet project and, while I really loved the concept, I found the tooling to be immature. This project’s tooling and documentation does looks better so I look forward to trying it out.
One thing I find missing with these unikernels though is IPSec support and Firewalls. I’d love to throw a unikernel image on DigitalOcean and have a secure software-defined IPSec tunnel.
- nderjung 5y agoIt's possible to create an IPSec + firewall based on the Click Modular Router[0] and run this on top of Unikraft[1]. [0]: https://github.com/kohler/click/wiki/IPsecEncap https://github.com/kohler/click/wiki/IPsecEncap (and other IPSec* elements) [1]: https://github.com/unikraft/app-click https://github.com/unikraft/app-click It could make for an interesting tutorial with a full Click-based IPSec router though! :)
- convolvatron 5y agoout of real curiosity - what would be the point of a firewall in a unikernel image? I mean presumably its to stop people from opening random ports. but if you bundle the application and you don't support a shell or forking processes in general then the only bound ports are those which the application explicitly opens. so what value in requiring someone to run around the interface and open it in the firewall as well?
- coredog64 5y agoYou might want to let your metrics system scrape a private endpoint published on a different port. Or you might have management task that you want to restrict to your internal network. Possible if you delegate to network hardware, but sometimes those asks are a PITA.
- speed_spread 5y agoOSv has been around for a while, I remember looking into it five years ago. What did you feel was missing in terms of tooling?