Big fan of Tailscale, yet I wonder whether it wouldn’t be better to make internal services securely available over the internet (zero trust rather than castle-and-moat). On the other hand, the former might be just to expensive for smaller organisations.
Everlag|3 years ago
The main painful thing I've found has been cert management. PKI, as usual, is not a solved problem.
I've managed to do some fun stuff using salt + nebula on the hobby side.
[0] https://github.com/slackhq/nebula
willnorris|3 years ago
adhdguy|3 years ago
xena|3 years ago
rkangel|3 years ago
kpolls|3 years ago
GCP's Identity Aware Proxy (IAP) comes free with the load balancer
paxys|3 years ago
whalesalad|3 years ago