5 ms·
As an industry, we are bad at deprecating old protocols like IPv4. This is a genius hack for a problem we have due to IPv6 not being adopted widely enough so th
by danrl 4y ago
As an industry, we are bad at deprecating old protocols like IPv4. This is a genius hack for a problem we have due to IPv6 not being adopted widely enough so that serving legacy IP users becomes a dropable liability to the business. The ROI is still high enough for us to “innovate” here. I applaud the solution but mourn the fact that we still need this.
I guess ingress is next, then? Two layers of Unimog to achieve stability before TCP/TLS termination maybe.
- dopylitty 4y agoI've been thinking a lot about this in my own enterprise and I've increasingly come to the conclusion that IP itself is the wrong abstraction for how the majority of modern networked compute works. IPv6, as a (quite old itself) iteration on top of IPv4 with a bunch of byzantine processes and acronyms tacked on is solving the wrong problem. Originally IP was a way to allow discrete physical computers in different locations owned by different organizations to find each other and exchange information autonomously. These days most compute actually doesn't look like that. All my compute is in AWS. Rather than being autonomous it is controlled by a single global control plane and uniquely identified within that control plane. So when I want my services to connect to each-other within AWS why am I still dealing with these complex routing algorithms and obtuse numbering schemes? AWS knows exactly which physical hosts my processes are running on and could at a control plane level connect them directly. And I, as someone running a business, could focus on the higher level problem of 'service X is allowed to connect to service Y' rather than figuring out how to send IP packets across subnets/TGWs and where to configure which ports in NACLs and security groups to allow the connection. Similarly my ISP knows exactly where Amazon and CloudFlare's nearest front doors are so instead of 15 hops and DNS resolutions my laptop could just make a request to Service X on AWS. My ISP could drop the message in AWS' nearest front door and AWS could figure out how to drop the message on the right host however they want to. I know there's a lot of legacy cruft and also that there are benefits of the autonomous/decentralized model vs central control for the internet as a whole but given the centralized reality we're in, especially within the enterprise, I think it's worth reevaluating how we approach networking and whether the continuing focus on IP is the best use of of our time.
- akira2501 4y ago> Rather than being autonomous it is controlled by a single global control plane and uniquely identified within that control plane. By default, sure. You can easily bring your own IPs into AWS and use them instead, and I don't think it's hard to imagine the pertinent use cases and risk management this brings.
- wpietri 4y ago> my laptop could just make a request to Service X on AWS I was looking for the "just" that handwaves away the complexity and I was not disappointed. How do you imagine your laptop expressing a request in a way that it makes it through to the right machine? Doing a traceroute to amazon.com, I count 26 devices between me and it. How will those devices know which physical connection to pass the request over? Remember that some of them will be handling absurd amounts of traffic, so your scheme will need to work with custom silicon for routing as well as doing ok on the $40 Linksys home unit. What are you imagining that would be so much more efficient that it's worth the enormous switching costs? I also have questions about your notion of "centralization". Are you saying that Google, Microsoft, and other cloud vendors should just... give up and hand their business to AWS? Is that also true for anybody who does hosting, including me running a server at home? If so, I invite you to read up on the history of antitrust law, as there are good reasons to avoid a small number of people having total control over key economic sectors.
- dopylitty 4y ago> How do you imagine your laptop expressing a request in a way that it makes it through to the right machine? Doing a traceroute to amazon.com, I count 26 devices between me and it. How will those devices know which physical connection to pass the request over? That's my whole point. You're thinking of it from an IP perspective where there are individual devices in some chain and they all need to autonomously figure out a path from my laptop to AWS. The reality is every device between me and AWS is owned by my ISP. They know exactly which physical path ahead of time will get a message from my laptop to AWS. So why waste all the time on the IP abstraction? > I also have questions about your notion of "centralization". Are you saying that Google, Microsoft, and other cloud vendors should just... give up and hand their business to AWS? AWS is just an example. Realistically a huge amount of traffic on the internet is going to 6 places and my ISP already has direct physical connections to those places. Maintaining this complex and byzantine abstraction to figure out how to get a message from my laptop to compute in those companies' infrastructure should not be necessary. And in general the more important part is within AWS' (or Microsoft's or enterprise X's) network why waste time on IP when the network owner knows exactly which host every compute process is running on? Instead of thinking of an enterprise network as a set of autonomous hosts that need to figure out a path between each other think of it as a set of processes running on the same OS (the virtual infrastructure). Linux doesn't need to do BGP to figure out how to connect two processes so why does your network?
- otabdeveloper4 4y agoYou misunderstand what "the internet" is. "The internet" is a process and methodology for connectivity between LANs. And 48 addressing bits is more than enough to solve this problem. TCP/IP is full of cruft and causes a shitload of unnecessary problems, but increasing the number of bits in the addressing space solves literally none of them.