3 ms·
Oh so that allows it to run in-process? That's cool, I did that for an HTTP forwarding thing a while back.
by RsmFz 2y ago
Oh so that allows it to run in-process?
That's cool, I did that for an HTTP forwarding thing a while back.
- PLG88 2y agoYes, indeed, this blog gives a great view on it - https://blog.openziti.io/go-is-amazing-for-zero-trust https://blog.openziti.io/go-is-amazing-for-zero-trust - using Golang and HTTP examples. My favourite part: "Now, your server has no listening ports on the underlay network. It's literally unattackable via conventional IP-based tooling. Seriously, stop and consider that for just a moment. By adopting an OpenZiti SDK into the server, all conventional network threats are immediately useless."
- RsmFz 2y agoWell that's also true for Firezone :) It's a tradeoff between in-process and out-of-process though. It's nice that Firezone Gateways don't have access to the service's memory space and can't crash the process, but it's also nice that an in-process Gateway equivalent doesn't need to loop through the network to reach its service.
- PLG88 2y agoMaybe we are referring to different things when we say 'process'... I am not aware (happy to be educated) of Firezone having SDKs to embed the zero trust overlay running directly in an application, i.e., in the app process and memory. Do they support this? I hear you on having 'out of process', that's why OpenZiti also has tunnellers for deploying on host as well as virtual appliances to run in the DMZ/VNET/VPC etc. I was only aware of Firezone supporting those 2 deployment models.