4 ms·
I would note to aborsy comment 'VPN server on a cloud instance, versus running a DERP/relay' that if the overlay is architected 'correctly' then it uses mTLS co
by PLG88 3y ago
I would note to aborsy comment 'VPN server on a cloud instance, versus running a DERP/relay' that if the overlay is architected 'correctly' then it uses mTLS connections between each hope while having E2E encryption between source and destination for the overlay. Net result is you do not have to trust the node as its never decrypting data while the edge runs in your own environment. Further, you cannot just impersonate a node.
You do have to trust the control/coordination server, though you could also run this in confidential compute.
Also, if you are interested in mesh networks, check out open source OpenZiti - https://github.com/openziti https://github.com/openziti