Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jefferai
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
jefferai
6y ago
Boundary will indeed give you a bearer token after authentication to present to take further actions in its API. So you'd authenticate to Boundary, get a bearer token, and use that to make one or more requests to connect to infrastruct
2.
▲
by
jefferai
6y ago
TCP targets (the only kind currently in Boundary) actually work with _any_ TCP connection. The `boundary connect <subcommand>` bits are just some CLI syntactic sugar around the main `boundary connect` command -- which works all by its
3.
▲
by
jefferai
6y ago
We don't have something natively, but you can control the address via BOUNDARY_ADDR env var or the -addr flag per-call, and you can use -token-name with the CLI to switch between named tokens, which can be sourced from different accoun
4.
▲
by
jefferai
6y ago
Without committing to any specifics, I'll say that we are very aware of use-cases where a daemon on the end host can provide enhanced benefits. As you can imagine we did quite a bit of research with our existing users/customers wh
5.
▲
by
jefferai
6y ago
In an immediate sense you could have targets point to services handled by Connect, so you'd have client -> Boundary worker -> local Connect entrypoint -> end service. We'll be looking more closely at other integration pos
6.
▲
by
jefferai
6y ago
Check out https://www.boundaryproject.io/docs/concepts/security/connec... for lots of details!
7.
▲
by
jefferai
6y ago
Generally speaking this is designed for accessing your own systems, not the systems of a third party being consumed as a SaaS. That said, any such provider that allows you to restrict the set of IPs allowed to make calls to the service woul
8.
▲
by
jefferai
6y ago
By "direct network access" we mean between the client and the end host. The Boundary worker node (which proxies traffic) would need to be able to make a network connection to the end host, and the client in turn would need to be a
9.
▲
by
jefferai
6y ago
As you say, it's a big question. But one way to start is by integrating this _within your VPN_ such that network access + credentials alone are not enough. With Boundary you could do this by setting up firewalls on the end hosts to onl
10.
▲
by
jefferai
8y ago
You can use Consul-Template ( https://github.com/hashicorp/consul-template ) -- yes, it really needs a rename -- to do this with Vault (or Consul).
11.
▲
by
jefferai
11y ago
S3 is one of the available storage backends. You only need consul/etcd/zookeeper if you want to have a high availability setup.
12.
▲
by
jefferai
14y ago
You didn't. Mirroring in this case refers to using git --mirror. You're assuming it works like a traditional file system or block level mirror, but it doesn't. Corruption would in most cases have been caught. The weak (and accidental) link