4 ms·
The approach my team takes is we put Wireguard gateways running on OpenBSD in front of network services. We go a step further and very carefully select what chi
by devaiops9001 3y ago
The approach my team takes is we put Wireguard gateways running on OpenBSD in front of network services. We go a step further and very carefully select what chips are used for the network interfaces and also attach a hardware random number generator to add to entropy.
Internal users' machines have these tunnels transparently loaded and running, configured by our internal GitOps-driven config management (SaltStack).
Has been pretty comfy so far.
- ahoka 3y agoKinda sounds like pure security theater, TBH. I don’t mean the jump hosts, but all the other stuff.