5 ms·
Show HN: OpenZiti Python SDK
- ekoby 4y agoI am happy to introduce OpenZiti Python SDK. It allows you to: * embed zero trust secure networking right into your Python application * run your Python services without any open network ports. Powered by: https://github.com/openziti/ziti https://github.com/openziti/ziti
- manfre 4y agoHow does Ziti compare to something like nats (https://nats.io https://nats.io)?
- ekoby 4y agoI am not deeply familiar with nats.io, so I could be wrong in my comparisons. OpenZiti is a connection-oriented overlay network vs NATS a messaging system. OpenZiti SDKs are more easily embeddable in existing applications as it does not require changes in networking semantics.
- PLG88 4y agoFWI, the OpenZiti project 'integrated' their Go SDK into NATS last year - https://www.youtube.com/watch?v=8V_HlDZy6M8&ab_channel=OpenZiti https://www.youtube.com/watch?v=8V_HlDZy6M8&ab_channel=OpenZ.... I say 'integrated' as it was a quick and dirty integration rather than anywhere near production ready.
- voidfunc 4y agoCongrats on the release! - Your former Orion pal, P :)
- linsomniac 4y agoThis is very cool, Python is my primary programming language and OpenZiti is something that looks promising for communication between public endpoints (like a Lambda receiver for Slack messages) and private infrastructure (like triggering a cron job to run).
- ekoby 4y agofunny you should mention this, here is another post covering exactly that: https://news.ycombinator.com/item?id=32924212 https://news.ycombinator.com/item?id=32924212
- linsomniac 4y agoThanks for that pointer, didn't see that.
- dec0dedab0de 4y agoAm I the only one who is having trouble understanding what this is doing, and why I would want to use it? Maybe I should have had that cup of coffee earlier.
- linsomniac 4y agoYou are not, every time I look at the OpenZiti site I get more confused, but I also can't really figure out why. The team behind OpenZiti is super helpful, and I wish I could provide them feedback like "This confused me" or "this isn't clear", but I can't really figure it out. My TL;DR of OpenZiti is: It is a meshed overlay with endpoint authentication and ACLs. Endpoints can be: application-embedded (think TLS) or system level (think PtP VPN) or routers to subnets (think routing VPN). One thing that took me a long time to wrap my head around is: You can incrementally implement OpenZiti by: setting it up as a traditional VPN, then start putting individual server endpoints directly on OpenZiti, then put individual services directly on the fabric (application embedded). OpenZiti team: Is this a fair TL;DR?
- ekoby 4y agoThis is a pretty accurate description of OpenZiti. The incremental approach is something that many of our customers go through: start with tunneling agents (quick and low investment), then transition to application embedded solutions
- billconan 4y agois it app embedded VPN?
- ekoby 4y agoIn the simplest terms, it's an application embedded VPN (on both client and server) The SDK allows you to integrate OpenZiti directly into your applications so that it can access network resources securely from anywhere in the world. This is based on strong identity so that the overlay cannot be access by untrusted endpoints. This is ensuring your application has zero trust in the network, WAN, LAN and even host OS - in fact, your app does not even need to know the IP and port to communicate with on the underlying host. Comparing to traditional VPNs this solution is a lot more secure -- instead giving you access to internal network, OpenZiti gives you access to specific service endpoints.
- __MatrixMan__ 4y agoHow does this compare with libp2p? Every time I try to use it I get the feeling that the python support was abandoned half-way, maybe OpenZiti would be better.
- ekoby 4y agothere are significant differences from libp2p: * strong identity support: authenticate before connect * it is service oriented vs point-to-point We would love for you to try OpenZiti it give us feedback :)
- __MatrixMan__ 4y agoIt'll be a bit. Gotta get standalone mode working before I go multiuser, but I absolutely will.
- ekoby 4y agoThe good news is you don't have to stand up your OpenZiti network to try it out. We have Ziti Edge Developer Sandbox (ZEDS) https://zeds.openziti.org https://zeds.openziti.org exactly for this reason. It is a simple way to try OpenZiti, and exercise OpenZiti SDKs.