3 ms·
Hi everyone! Firezone CEO here. Someone just clued me into this thread. Unfortunately I’m in and out of Internet service today but I’ll do my best to answer qu
by jamilbk 4y ago
Hi everyone!
Firezone CEO here. Someone just clued me into this thread. Unfortunately I’m in and out of Internet service today but I’ll do my best to answer questions.
As noted by others, Firezone isn’t really aiming to be a mesh networking tool like Tailscale, but more of a classic east-west VPN similar to OpenVPN Access Server. We also expose simple controls for managing egress firewall rules.
We have a big release planned next week to bring OIDC auth and the ability to manage multiple WireGuard networks, plus Docker support and more firewall + multisite features in the pipeline for later this summer.
We have a one-line install script for Linux at our repo if you’d like to give it a whirl! Grateful for any and all feedback.
https://github.com/firezone/firezone https://github.com/firezone/firezone
- loudthing 4y agoThanks for posting. What are the use cases for Firezone exactly? Is the intention to simplify networking configuration in data centers? (as opposed to the zero config nature of Tailscale devices that could be anywhere on the internet?)
- KennyBlanken 4y ago> We also expose simple controls for managing egress firewall rules. Unless user-tracking telemetry is blocked, in which case, apparently your CLI tools stop working? https://news.ycombinator.com/item?id=31542047 https://news.ycombinator.com/item?id=31542047 Edit: dunno if that comment was deleted because the author was wrong about their PiHole blocking telemetry causing commands to fail, if they were harassed into deleting it, or what. I guess I'll give you the benefit of the doubt that there was something else going on with their network that caused commands to fail, but you're still getting side-eye for engaging in telemetry/usage tracking.
- SadTrombone 4y agoThe post you're linking to seems to have been deleted.
- xanaxagoras 4y agoHi, I deleted that post because it had something in it I didn't want forever recorded on the internet. Nobody harassed me and I wasn't wrong. One of my pihole blocklists includes telemetry.* which matches some network call made by the command you run to update the Firezone config. Pihole returns "0.0.0.0" for hostnames it blocks and the error that's raised ends up coming form openssl. Later I discovered there are 2 options at the bottom of the /etc/firezone/firezone.rb config file, commented out, that allow you to disable the telemetry. With these options turned on the error no longer occurs.
- jamilbk 4y agoWe don't actively block any functionality when a user blocks telemetry -- that's definitely an unintended side effect and bug. You'll have more luck disabling telemetry in the config file with `default['firezone']['telemetry']['enabled'] = false` documented here: https://docs.firezone.dev/docs/reference/configuration-file/ https://docs.firezone.dev/docs/reference/configuration-file/ We could definitely clarify how to disable telemetry better and we should make sure nothing breaks when telemetry is blackholed instead of disabled. I've opened https://github.com/firezone/firezone/pull/658 https://github.com/firezone/firezone/pull/658 to get these addressed.
- Dowwie 4y agoCan you share your experiences working with Elixir for this kind of project? Sharing anything about strengths, weaknesses, or general insights would be appreciated.
- jamilbk 4y agoSure! Elixir's been great. Phoenix is a joy to work with, and many of the concurrency primitives built into OTP make it the perfect foundation for a product like this. And rustler makes it super easy to add low-level / native code. I will say the big downside to using Elixir is that distributing releases is a bit cumbersome. `mix release` expects that you're building on the same OS / version as you'll be running on, though we're looking into using something like burrito [1] to help alleviate this. [1] https://github.com/burrito-elixir/burrito https://github.com/burrito-elixir/burrito