Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ekoby
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Secure Caddy server with OpenZiti
(blog.openziti.io)
2 points
by
ekoby
3y ago
|
0 comments
2.
▲
Use OpenZiti to secure your monitoring
(blog.openziti.io)
14 points
by
ekoby
4y ago
|
6 comments
3.
▲
by
ekoby
4y ago
In this blog article we show how we embedded OpenZiti SDK to secure monitoring collection with beats/logstash
4.
▲
Show HN: Build your gRPC apps with embedded zero trust networking
(github.com)
15 points
by
ekoby
4y ago
|
0 comments
5.
▲
by
ekoby
4y ago
The good news is you don't have to stand up your OpenZiti network to try it out. We have Ziti Edge Developer Sandbox (ZEDS) https://zeds.openziti.org exactly for this reason. It is a simple way to try OpenZiti, and exercise
6.
▲
by
ekoby
4y ago
This is a pretty accurate description of OpenZiti. The incremental approach is something that many of our customers go through: start with tunneling agents (quick and low investment), then transition to application embedded solutions
7.
▲
by
ekoby
4y ago
at this time OpenZiti connection are guaranteed-delivery (like TCP). We are evaluating offering lossy connections in the future. At the edges connection are always outbound and are seen as mTLS to the firewalls. the application payloads are
8.
▲
by
ekoby
4y ago
Absolutely, from your application's view it is just a socket that can live and be used to send/receive data indefinitely
9.
▲
by
ekoby
4y ago
there are significant differences from libp2p: * strong identity support: authenticate before connect * it is service oriented vs point-to-point We would love for you to try OpenZiti it give us feedback :)
10.
▲
by
ekoby
4y ago
> Also what the threat model is, and how ziti solves it. Your service (anything that accepts incoming connections) is never exposed to open internet. any incoming connections are guaranteed to be from authenticated and authorized clients
11.
▲
by
ekoby
4y ago
I am not deeply familiar with nats.io, so I could be wrong in my comparisons. OpenZiti is a connection-oriented overlay network vs NATS a messaging system. OpenZiti SDKs are more easily embeddable in existing applications as it does not req
12.
▲
by
ekoby
4y ago
In the simplest terms, it's an application embedded VPN (on both client and server) The SDK allows you to integrate OpenZiti directly into your applications so that it can access network resources securely from anywhere in the world. T
13.
▲
by
ekoby
4y ago
funny you should mention this, here is another post covering exactly that: https://news.ycombinator.com/item?id=32924212
14.
▲
by
ekoby
4y ago
I am happy to introduce OpenZiti Python SDK. It allows you to: * embed zero trust secure networking right into your Python application * run your Python services without any open network ports. Powered by: https://github.com/
15.
▲
Show HN: OpenZiti Python SDK
(openziti.io)
41 points
by
ekoby
4y ago
|
25 comments
16.
▲
by
ekoby
4y ago
there are few things that improve your defense posture: - DDOS attacks can only attack the fabric and not the business logic service. Fabric nodes can be easily moved around or added to change attack surface. - you can have multiple service
17.
▲
by
ekoby
4y ago
I created this project to demonstrate the ease of embedding OpenZiti SDK in golang applications. The server is a fully functional MQTT server listening on the overlay network without any open listening ports. The client can be used for test
18.
▲
MQZiti – Zero Trust MQTT server and client
(github.com)
60 points
by
ekoby
4y ago
|
16 comments