Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PLG88
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
211.
▲
What's PrometheuZ? Its been Zitified to scrape anything from anywhere
(openziti.github.io)
6 points
by
PLG88
4y ago
|
1 comments
212.
▲
by
PLG88
4y ago
Basically we forked the latest Prometheus and embedded the golang OpenZiti SDK into the server to allow listening and dialing over the overlay network. Find that code at https://github.com/openziti-test-kitchen/promethe
213.
▲
by
PLG88
4y ago
This speaks to a strong nuance, its not only the closed inbound ports meaning no external network attacks, the strong identity allow the user to be anywhere (home, coffe shop, holiday) rather than tied to an IP while Sec team also get massi
214.
▲
by
PLG88
4y ago
When taking another look, you may find this brief set of 'superpowers' useful - https://www.youtube.com/playlist?list=PLMUj_5fklasKF1oisSSuL... . This includes closing all inbound ports (or FW rules) so that the ap
215.
▲
by
PLG88
4y ago
We wanted to stop external network attacks on our internal development environment while allowing tools like Jenkins to connect to other internet based tools such as GitHub. We do not want to have any inbound ports or deal with VPNs, ACLs,
216.
▲
This is the Way: Invisible Jenkins
(netfoundry.io)
39 points
by
PLG88
4y ago
|
39 comments
217.
▲
by
PLG88
4y ago
I like OpenZiti - https://openziti.github.io/ . It can be embedded inside anything. They recently did it to Prometheus and are working on Ansible - https://openziti.github.io/articles/zitification/p
218.
▲
by
PLG88
4y ago
Wow, some awesome work here. I would be interested to know your thoughts on OpenZiti ( https://openziti.github.io/ ). Its an open source project that allows you to embed private connectivity into your app using one of the man
219.
▲
by
PLG88
4y ago
OpenZiti has an architecture of 'Edge' and 'fabric'. The Edge is at source and destinatation and outbound connects into the fabric. The fabric is SDN, edge connects and authenticates/authorises to controller based o
220.
▲
by
PLG88
4y ago
You can literally embed private, outbound-only connectivity into your application code using one of the many SDKs - C, Java, Go etc etc... here is a good overview https://ziti.dev/ . As you can embed inside you app, you can
221.
▲
by
PLG88
4y ago
Yes, outbound only is great for client side and for me table stakes. OpenZiti allows you to make the server side outbound only too. Do you care about Log4Shell or Spring4Shell when your server is dark to the internet? Java Magazine recently
222.
▲
by
PLG88
4y ago
You should checkout the opensource project OpenZiti ( https://openziti.github.io/ ). It has its own internal PKI system so you dont need to (but can) like to an external 3rd party. It also allows you to close all inbound port
223.
▲
by
PLG88
4y ago
You should checkout the opensource project OpenZiti ( https://openziti.github.io/ ). It has its own internal PKI system so you dont need to (but can) like to an external 3rd party. It also allows you to close all inbound port
224.
▲
by
PLG88
4y ago
Here is another (sort of), OpenZiti - https://openziti.github.io/ . OpenZiti provides a mesh overlay network built on zero trust priinciples with outbound only connections so that we do not need inbound ports or link listene
225.
▲
by
PLG88
4y ago
Zero trust is a whooly term which means different things to different people, it's more of a strategya and principles than a technology. Ultimately you will have to trust something and we want to make that as small trust relationship a
226.
▲
by
PLG88
5y ago
What are your thoughts on zero trust from OpenZiti? - https://openziti.github.io/
227.
▲
by
PLG88
5y ago
I like the sound of these dark services! Must reduce a lot of attack vectors.
228.
▲
by
PLG88
5y ago
Agreed, with a couple of caveats: - based on the perenial patch Tuesday issues I am surprised it did not happen sooner. - zero trust is a journey. we should accept that networks cannot be secure and instead look to implement principles of Z
229.
▲
by
PLG88
5y ago
It saddens me that Microsoft cannot properly implement zero trust principles or account based access control to their DevOps environment. VDI and VPNs are not secure, no networks are secure!
230.
▲
by
PLG88
5y ago
Makes sense. Ziti could still be used on the dataplane to provide higher security on top of Cilium. Could be worth having a chat with the team from Ziti, I know they are always interested to chat on things they can zitify - e.g., https:&#
231.
▲
by
PLG88
5y ago
Also, have you considered embedding open source OpenZiti? It would put a zero trust dataplane into the platform so that applications could be deployed anywhere and only require outbound internet. No DNS, no VPNs, no complex FWs or rule, no
232.
▲
by
PLG88
5y ago
Very cool. Multi-cloud should be super easy so that we can choose where to put workloads. Have you considered polling the cloud provider APIs to make hosting decisions based on spot pricing etc??
233.
▲
by
PLG88
5y ago
https://www.oreilly.com/library/view/zero-trust-networks/978... This is where I cut mt teeth on ZT. Is there any specific area of ZT that you are interested in or problem you are trying to solve?
234.
▲
by
PLG88
5y ago
I don't work for them, but saw this from Ozone on how they use OpenZiti - https://ozone.one/blog/ozone-zitifies-private-kubernetes-dep...
235.
▲
by
PLG88
5y ago
Or just close all inbound ports so that log4shell cannot be compromised. This can be done by embedding opensource zero trust connectivity into your app with an SDK.
236.
▲
HN: How to Secure Your Dev Resources with Ziti
(actieve.medium.com)
28 points
by
PLG88
5y ago
|
5 comments
237.
▲
by
PLG88
5y ago
We use ZSSH based on OpenZiti so that the SSH client itself has zero trust, private connectivity embedded in the SSH client (i.e., clientless) - https://ziti.dev/blog/zitifying-ssh/
238.
▲
by
PLG88
5y ago
We put all our DevOps tools behind Open Ziti (ziti.dev) which ensures we do not need any public IPs (unlike a VPN or bastion) while giving granular access control for only trusted users.
239.
▲
by
PLG88
5y ago
Why not just not trust the network or host at all. Put private connectivity inside trusted code using an SDK. Then the trusted apps can only communicate to devices/apps defined and nothing else. Untrusted code cannot access the trusted
240.
▲
by
PLG88
5y ago
For me, the answer to 'hardening' is to use an open source zero trust solution which is always outbound only thereby cannot be subject to network level attacks (OSI 3-5), e.g., DDoS, brute force, CVE exploit etc
More ›