Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
qrkourier
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
qrkourier
2y ago
At a glance, the RunPod's serverless and pod options would probably work well with OpenZiti. I didn't explore their vLLM option. Using OpenZiti w/ Serverless probably means integrating an OpenZiti SDK with your serverless app
2.
▲
by
qrkourier
2y ago
> This is awesome -- I really like my current admission controller though (Traefik), it's FANTASTIC. I think moving ingress controllers might be a large lift for people (it would be for me). Clarification: You could use Traefik'
3.
▲
How to Run OpenZiti in Kubernetes in Docker
(blog.openziti.io)
3 points
by
qrkourier
2y ago
|
0 comments
4.
▲
by
qrkourier
2y ago
I worked on a minimal self-hosted ziti for Docker here https://github.com/openziti/ziti/tree/release-next/quickstar... and minimal self-hosted zrok (includes ziti) for Docker here https://docs
5.
▲
by
qrkourier
4y ago
True, the tools used by risk managers will have to adapt to overlays if overlays (software defined networks that look like encrypted noise on the wire) are as inevitable as they appear to be. It's kind of an arms race and it only makes
6.
▲
by
qrkourier
4y ago
I see what you mean. I'll make sure to suggest adding it in those places, then! There's another post about the Python SDK in https://news.ycombinator.com/item?id=32923851 and the repo is https://github.
7.
▲
by
qrkourier
4y ago
That's a neat angle. I reckon you could position the self-hosted runner network-adjacent a private CI server and poke it directly from behind the firewall with a GitHub Actions job.
8.
▲
by
qrkourier
4y ago
Glad you got it updated before you missed an event! That's the worry that made me look for something flexible and software-defined that I could run in GitHub Actions.
9.
▲
by
qrkourier
4y ago
That's useful that ngrok has centralized webhook verification! It's meaningful security for the first hop from GitHub to ngrok.
10.
▲
by
qrkourier
4y ago
The proxy idea is interesting too. Does a webhook proxy entail a polling model for events? That is, does the private server have to poll the proxy to receive the webhook? I wanted the GitHub event to push to trigger actions on the private s
11.
▲
by
qrkourier
4y ago
Did you find a way to auto-update your firewall from the dynamic allow list in the GitHub API?
12.
▲
by
qrkourier
4y ago
Also relevant, sending a GitHub webhook to private Jenkins server with custom params: https://news.ycombinator.com/item?id=31503429
13.
▲
Show HN: Send a GitHub webhook to a private URL
(github.com)
72 points
by
qrkourier
4y ago
|
21 comments
14.
▲
by
qrkourier
4y ago
Re: DNS .53 is the default for the built-in nameserver in `systemd-resolved`, but there's not collision with the OpenZiti tunneler for Linux because it implements systemd's API and creates a tun device and nameserver in a configur
15.
▲
by
qrkourier
4y ago
A strict VPN is still a perimeter that trusts addresses which are not really identities.
16.
▲
by
qrkourier
4y ago
Even if you nail the configuration and have nothing but sweet love for your favorite VPN it's still a perimeter security model and there's no real assurance that only your friends are inside that perimeter. I'll bet you that&
17.
▲
by
qrkourier
4y ago
To your point, not all SaaS or vendors with integrations let you run your own code. If they do allow it there's probably an OpenZiti-native way to build-in the connectivity you need. One alternative is running a tunneler like our users
18.
▲
by
qrkourier
4y ago
Good job avoiding public internet exposure, but the problem with being "on the VPN" is that it has all the problems of the internet at a smaller scale, so you're still exposed to an untrustworthy network. I'd say that&#x
19.
▲
by
qrkourier
4y ago
I think the flexibility of operating independently of IP addresses is the key distinction of this approach. It also works for the web UI, not just the webhooks from GitHub.
20.
▲
by
qrkourier
4y ago
Author here, I want to learn more about ZeroTier too. I overlooked it for this project because it supports layer 2 and I needed tighter coupling of application+policy than layer 2 provides. Admittedly, I don't yet know enough about Zer
21.
▲
by
qrkourier
4y ago
Yes: https://github.com/openziti/ziti-sdk-c/
22.
▲
by
qrkourier
4y ago
I guess it's like anything else. You can trust someone a little to manage your crypto keys or you can do it yourself whether its PKI or a Bitcoin wallet. You have to know and do more to trust less. For me, it's a really great valu
23.
▲
by
qrkourier
5y ago
https://tailscale.com/kb/1148/tailscale-vs-nebula/
24.
▲
by
qrkourier
5y ago
We've all taken that risk at some point. Glad you found a solution!