3 ms·
We just block all external ip addresses except for github's in nginx for webhooks. To access the ui you need to be in the vpn.
by 89vision 4y ago
We just block all external ip addresses except for github's in nginx for webhooks. To access the ui you need to be in the vpn.
- dovholuknf 4y agoIt definitely was *the way* to do it before OpenZiti and other zero trust overlay networks started to take off. Being "in the VPN" is similar to participating on the OpenZiti overlay network. VPNs allow for horizontal movement much easier than being on an OpenZiti zero trust overlay network does. With OpenZiti you don't need any holes in your firewall open. That's a pretty good reason to consider moving away from VPNs to a zero trust overlay like OpenZiti in my book, but I'm biased, I work on the project. Embracing the zero trust networking mindset is definitely a change of pace but I think it's worth considering.
- qrkourier 4y agoGood job avoiding public internet exposure, but the problem with being "on the VPN" is that it has all the problems of the internet at a smaller scale, so you're still exposed to an untrustworthy network. I'd say that's the core tenant of so-called "zero trust" philosophy.