Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
geoctl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
geoctl
1y ago
Thank you. I will definitely work on making the README more concise and hopefully more useful and easy to understand.
62.
▲
by
geoctl
1y ago
I admit that the "next-gen" word might sound cheesy. As I said in the other reply, the more correct definition for Octelium is: a unified zero trust secure access platform. However, as I said this is a term that nobody would relat
63.
▲
by
geoctl
1y ago
I honestly don't understand where the "sales pitch" part is. This project has been so far a solo effort and I am the one who basically wrote all the code. It's not like this is some VC-backed product where I am a marketi
64.
▲
by
geoctl
1y ago
There are lots of common functionalities between API and AI gateways. It would be much easier for you to check out the examples in the docs: For the AI gateway: https://octelium.com/docs/octelium/latest/manage
65.
▲
by
geoctl
1y ago
I'd appreciate if you could provide me a list of those buzzwords so that I can improve the readme.
66.
▲
by
geoctl
1y ago
Octelium is a zero trust architecture not a p2p VPN even though it can seamlessy operate as a WireGuard/QUIC-based remote access VPN among other things. Its architecture is closer to Cloudflare Access, Teleport, etc... as it provides d
67.
▲
by
geoctl
1y ago
Thank you. I understand it's hard to concisely define what Octelium is because it is designed as a unified/generic secure/zero trust access platform, a term that almost nobody would relate to. It's more of a generic Kube
68.
▲
Show HN: Octelium – FOSS Alternative to Teleport, Cloudflare, Tailscale, Ngrok
(github.com)
358 points
by
geoctl
1y ago
|
151 comments
69.
▲
by
geoctl
1y ago
I believe there is more to the problem than just laziness from the relying party side. The problem is what do you verify against? It's not as easy as in, for example, TLS handshake where browsers/HTTP clients have well-defined roo
70.
▲
by
geoctl
1y ago
Great effort. I honestly doubt that any B2C or even the vast majority of B2B relying parties do verification of attestation statements during registration which means the relying party never really knows whether the authenticator's pub
71.
▲
by
geoctl
1y ago
Apart from 1 and 3, probably everything else can be added today if the people in charge have the will to do that, and that's assuming that I am right and these points are actually that important to be standardized. However the big ente
72.
▲
by
geoctl
1y ago
I never said that CRDs are tied to Golang, I said that the experience of compiling CRDs, back then gen-controller or whatever is being used these days, to Golang types was simply ugly partly due to the flaws of the language itself. What I m
73.
▲
by
geoctl
1y ago
I haven't used CRDs myself for a few years now (probably since 2021), but I still remember developing CRDs was an ugly and hairy experience to say the least, partly due to the flaws of Golang itself (e.g. no traits like in Rust, no mac
74.
▲
by
geoctl
1y ago
You can very easily build and serialize/deserialize HCL, JSON, YAML or whatever you can come up with outside Kubernetes from the client-side itself (e.g. kubectl). This has actually nothing to do with Kubernetes itself at all.
75.
▲
by
geoctl
1y ago
I would say k8s 2.0 needs: 1. gRPC/proto3-based APIs to make controlling k8s clusters easier using any programming language not just practically Golang as is the case currently and this can even make dealing with k8s controllers easier
76.
▲
by
geoctl
1y ago
Great work. I've always wondered if WASM could actually be used as a more generic alternative alternative to eBPF where you could actually do more complex logic than the average eBPF program at the kernel level and still have customize
77.
▲
by
geoctl
1y ago
Thank you. The harsh reality is that I've been undecided on the license for years while working the project (the initial private repo had it all AGPLv3 as opposed to only the Cluster side in this public repo). The reason for choosing i
78.
▲
Show HN: Octelium – L7-Aware ZeroTrust Remote Access ZTNA over WireGuard and K8s
(github.com)
2 points
by
geoctl
1y ago
|
3 comments
79.
▲
Show HN: Octelium – FOSS L7-Aware Zero Trust Access/PaaS Platform over WireGuard
(github.com)
3 points
by
geoctl
1y ago
|
0 comments
80.
▲
by
geoctl
1y ago
Thank you. Actually one of the very hardest things for me working on Octelium is basically how to describe it concisely and clearly and I still can't say that I have an answer, that's why I prefer to describe it as a "unified
81.
▲
Show HN: I Spent Years Building a FOSS Unified Zero Trust Secure Access Platform
(github.com)
7 points
by
geoctl
1y ago
|
3 comments
82.
▲
by
geoctl
2y ago
I would argue that dev containers are more complicated than CI even though they share many of the challenges (e.g. devcontainers might need to load 10s or 100s of GBs to start and are write heavy). I would also argue that userns/rootle
83.
▲
by
geoctl
2y ago
Firecracker is more comparable to container runtimes than to orchestrators such as K8s. You still need an orchestrator to schedule, manage and garbage-collect all your uVMs on top of your infrastructure exactly like you would do with contai
84.
▲
by
geoctl
2y ago
I've worked on something similar to gitpod in a slightly different context that's part of a much bigger personal project related to secure remote access that I've actually spent a few years building now and hope to open sourc
85.
▲
by
geoctl
2y ago
Still looks more interesting than that Next.js landing page template used by every startup these days.