4 ms·
I think "no buzzwords" would be further in the direction of: "This software let's you set up peer to peer networking between your devices, expose them to the i
by maxmcd 1y ago
I think "no buzzwords" would be further in the direction of:
"This software let's you set up peer to peer networking between your devices, expose them to the internet, run applications on them, view useful runtime information, and integrate easily with cloud providers and infrastructure you're familiar with."
- geoctl 1y agoThank you. Octelium, however, does not operate as p2p and does not directly connect devices since that by itself contradicts the whole point of zero trust. It provides remote access to resources, or even sub-resources via L7 access control (e.g. allow access to some HTTP paths to some users based on identity/context/request content, etc...), not completely to "devices" or to complete subnets.
- dudeinjapan 1y agoHow about: “Octelium is a secure, policy-based access gateway to your HTTP services, with both VPN tunnel-based and OAuth/zero-trust modes available. (And it can do a lot more!)”
- geoctl 1y agoThank you. I think your description is great but I, as a user myself, might see it as an identity-aware proxy (i.e. something like Pomerium and Ory Oathkeeper IaPs which are great projects) as opposed to a complete Kubernetes-tier platform that does the entire process of remote access, access control, visibility and auditing, user and identtiy management, centralized policy management, etc... from a data-plane and control-plane perspective for an arbitrary number of resources that need to be protected.
- dudeinjapan 1y agoMuch of this writing is about finding the right level of detail to communicate the core ideas. “Octelium is a full-featured access control platform, which provides API gateways and/or VPN tunnels to your HTTP services, paired with an intuitive user, policy, and auditing backplane and policy-as-code.” Something like the above would be much more enticing to potential users including myself. I can get a rough idea of what I can actually use it for and how it can be integrated into my existing stack—and if there are more features I’ll be pleasantly surprised when I read the docs!
- geoctl 1y agoI completely agree with you. And tbqh since almost everybody in the thread is complaining about the README then I must be really doing something wrong explaining Octelium and what it does. I will certainly put more effort to make the README and especially the main description section more useful and easier to understand without transforming it into more of a marketing pitch. As I mentioned in other replies, it's actually really hard to concisely describe fairly complex projects (e.g. Kubernetes, Istio, etc...), especially to newcomers. But I will definitely do my best to improve the docs and README. Thank you really for your insightful comments.
- dudeinjapan 1y agoOne more pointer would be to be very explicit on the homepage about the problems the product solves. For example, many organizations use a mix of gated HTTP over public internet AND VPN, each one will have its own vendor auth product(s), user whitelisting, it's difficult to control or regularly audit. Octelium centralizes this management and gives admins the flexibility to control how services are exposed and to whom, presumably via simple policy change git commits. SOC2, etc. then becomes a breeze to export the state of the world, onboard/offboard employees, etc. Defining the product in terms of use cases/problems/solutions rather that competing alternatives (Tailscale, Okta, ORY Hydra, etc.) will go a long way to increase clarity.
- geoctl 1y agoThank you, I will definitely add more kind of less-technical information on the homepage to make it easier to understand for business people. As for comparisons, I have been actually reluctant to do it because I don't think I can ever do a truly neutral comparison myself and I believe it should come from neutral parties such as blogs as well as users trying to discover the best solution that works for their own use case. But since I have been asked multiple times already I will probably add some comparisons soon.
- noname120 1y ago
- bdesimone 1y agoQuick note since it was mentioned. Pomerium does support Kubernetes at pretty much every level you mentioned (although I'm not entirely sure what a "a complete Kubernetes-tier platform" means) including: - "remote access" : https://www.pomerium.com/docs/capabilities/kubernetes-access https://www.pomerium.com/docs/capabilities/kubernetes-access - "access control" https://www.pomerium.com/docs/capabilities/authorization https://www.pomerium.com/docs/capabilities/authorization - "visibility and auditing" : https://www.pomerium.com/docs/capabilities/audit-logs https://www.pomerium.com/docs/capabilities/audit-logs - "user and identtiy management" https://www.pomerium.com/docs/capabilities/authentication https://www.pomerium.com/docs/capabilities/authentication to which I'd add device identity as well. - "centralized policy management": https://www.pomerium.com/docs/capabilities/authorization https://www.pomerium.com/docs/capabilities/authorization & https://www.pomerium.com/docs/internals/ppl https://www.pomerium.com/docs/internals/ppl - deployments using Ingress Controller or GatewayAPI https://www.pomerium.com/docs/deploy/k8s/ingress https://www.pomerium.com/docs/deploy/k8s/ingress, https://www.pomerium.com/docs/deploy/k8s/gateway-api https://www.pomerium.com/docs/deploy/k8s/gateway-api - "for an arbitrary number of resources" not sure what to link to but there's no limit here Congrats on the release. I saw your thread on MCP and completely agree with the approach. Happy to trade notes :)
- geoctl 1y agoI apologize if my reply was seen as critical in any way. I only wanted to make a difference between Octelium as a complete platform compared to Pomerium (I meant the open source project not the entire Enterprise offering which is obviously a complete BeyondCorp solution) and Ory Oathkeeper as identity-aware proxies. A more technical description for Octelium is that it is for IaPs similar to what Kubernetes is for containers. It simply provides a complete control plane to manage and deploy IaPs on top of Kubernetes itself. In fact, I am a fan of Pomerium and their work (I still remember your great work related to Golang's Webauthn and its attestation-related stuff ~3 years ago) if you're part of the team. Funnily enough, Octelium started as a sidecar ext_authz svc for Envoy instances to operate as an IaP but I ended up creating my own Golang-based IaP, Vigil, from scratch because Envoy was just nothing but pain outside HTTP-based resources.