4 ms·
Thanks for the insights. OpenZiti can definitely replace Wireguard, I am have a long form comparison (which I need to publish soon) if you want me to share? Pe
by PLG88 4y ago
Thanks for the insights. OpenZiti can definitely replace Wireguard, I am have a long form comparison (which I need to publish soon) if you want me to share?
Performance wise, it depends. Wireguard is UDP-based so for some use cases it gets awesome performance but not all, and often requires tweaking to optimise. OpenZiti is TCP out of the box (this year we will move it to UDP with optimisations to deliver TCP reliability with a protocol we have built - https://github.com/openziti/ziti/blob/v0.19.8/doc/transwarp_b1/transwarp_b1.md https://github.com/openziti/ziti/blob/v0.19.8/doc/transwarp_...). You can see a comparison here - https://netfoundry.io/benchmark/benchmarking%20open%20source%20networking.pdf https://netfoundry.io/benchmark/benchmarking%20open%20source...
It would be interesting to understand too, if you replace Buzzfeed SSO with OpenZiti, are there any features you would want OpenZiti to have (i.e., can share that they exist already or we learn where we potentially need to do development)?
You can 100% use OpenZiti for gaming use cases, I have a couple of colleagues who have written blogs on it:
- https://blog.openziti.io/set-up-a-secure-multiplayer-minecraft-server https://blog.openziti.io/set-up-a-secure-multiplayer-minecra...
- https://www.reddit.com/r/selfhosted/comments/v8222j/gaming_on_the_go_host_your_zerotust_solution_and/ https://www.reddit.com/r/selfhosted/comments/v8222j/gaming_o...
- heywoodlh 4y ago> are there any features you would want OpenZiti to have One thing I'm not seeing in docs is a way to use existing third-party identity systems (such as Okta, LDAP, Google Oauth, etc.). Does OpenZiti have a way to use external identities? As an example, with Buzzfeed SSO, I can expose an HTTP application to the world, but limit who can actually access it (such as my brother who can use his Gmail to authenticate to certain services I have shared with him).
- PLG88 4y agoHere is a blog too on external IdP for OpenZiti - https://blog.openziti.io/openziti-authentication-api-integrations https://blog.openziti.io/openziti-authentication-api-integra...
- dovholuknf 4y agoThe short answer is "probably". It depends on what you are doing, how you're doing it etc. But I think you might be looking for something like this? https://openziti.github.io/docs/core-concepts/security/authentication/external-jwt-signers/ https://openziti.github.io/docs/core-concepts/security/authe... Also we have already support 3rd party CAs too. It's a complex topic though so "it depends" is probably the best answer.