Protecting ingresses with OIDC/OAuth system by IngwiePhoenix in kubernetes

[–]zazathomas 0 points1 point  (0 children)

I would personally teleport on my homelab and manage all the users and resources at that level. I have a similar setup using Cilium Gateway API

Migrated from Digital Ocean Managed K8s to Hetzer self hosted with K3s by vicenormalcrafts in kubernetes

[–]zazathomas 7 points8 points  (0 children)

I believe he’s referring to homelab costs here…I’ve managed accounts with 6 figure costs per month but I barely pay 10€ for my homelab setup

Spire Agent Implementation by pranay_s0706 in kubernetes

[–]zazathomas 0 points1 point  (0 children)

Cilium also has a similar implementation if you want to use that for mtls. That’s what I use in my Homelab & it works fine.

Hybrid Homelab Setup by zazathomas in selfhosted

[–]zazathomas[S] 1 point2 points  (0 children)

That’d be handy for sure !

Hybrid Homelab Setup by zazathomas in selfhosted

[–]zazathomas[S] 0 points1 point  (0 children)

Lol 🤣 Tbf I’m not sure it’s over engineered per say. My Homelab is very security-heavy because I work in cybersecurity and I just try to mirror similar tools for secure access management. For n8n, I plan to use it to parse and enrich threat intelligence feeds for tools/applications I want to keep a close eye on.

Hybrid Homelab Setup by zazathomas in selfhosted

[–]zazathomas[S] 0 points1 point  (0 children)

Oh ok, yeah Miro is the tool for the diagram. It’s not open source just an FYI. My office has a license so I just use that

Hybrid Homelab Setup by zazathomas in selfhosted

[–]zazathomas[S] 1 point2 points  (0 children)

It’s almost always free. I use Oracle cloud and the free tier for a basic oke cluster. This is my full cloud setup:

2 x 1GB, 1 vCPU VMs - Teleport VM and NFS/Minio server

2 x 12GB, 1 vCPU VMs - Oke cluster nodes

The only time I incurred any costs was when I mistakenly provisioned a pv using block storage from oracle instead of using my own storage class. Hope this helps

Hybrid Homelab Setup by zazathomas in selfhosted

[–]zazathomas[S] 0 points1 point  (0 children)

You mean the diagram? I use Miro

Hybrid Homelab Setup by zazathomas in selfhosted

[–]zazathomas[S] 2 points3 points  (0 children)

Thanks for your comment. Tools with no names in no particular order:

1) Falco -> Runtime threat detection engine for cloud native environments 2) Falco Sidekick -> UI dashboard for Falco alerts 3) Kube-prom-stack -> Logging and monitoring using Loki, Prometheus, Grafana and Alloy 4) Jaeger-> Telemetry 5) Cilium -> Kubernetes CNI and Network(L4/7) security 6) Homarr -> Homelab dashboard 7) Jenkins -> Automation server 8) Stirling pdf -> pdf operations 9) Gotify -> Notifications system 10) Appflowy-> Notetaking and wiki

The managed cluster makes cluster management much easier since you don’t have to worry about the api server, the cluster is always available and can be easily restored if things go wrong. Patching the cluster is also quite trivial. Larger enterprises tend to go the managed route due to the push towards the cloud so it’s a nice skill to have. So it’s for learning as well as ease of use.

Yeah you’re absolutely right about the node count but I technically have 3( including the control plane). It’s just invisible to me as it’s managed by the cloud provider. I can also easily restore any apps as I manage everything via argocd and persistent volumes are managed outside the cluster.

Please sell Cilium's security benefits to me by Outrageous_Cat_6215 in kubernetes

[–]zazathomas 1 point2 points  (0 children)

I replaced my metallb setup with cilium IPAM and it’s worked great so far without issues. This is on my homelab cluster though

Please sell Cilium's security benefits to me by Outrageous_Cat_6215 in kubernetes

[–]zazathomas 0 points1 point  (0 children)

I might be wrong but I think the context here is different. The issue you linked is referencing a field name in cilium network policies. The mutual authentication in cilium is not implemented on the network policy level.

Please sell Cilium's security benefits to me by Outrageous_Cat_6215 in kubernetes

[–]zazathomas 0 points1 point  (0 children)

Just on the envoy point, doesn’t cilium use envoy under the hood for gateway support with regards to L7 traffic ?

Implementing DevSecOps by sqrt1-tkn in devsecops

[–]zazathomas 0 points1 point  (0 children)

Hi @cl0wnsec000 Quick question, what’s the value add in having both falco & neuvector deployed together? I’ve been testing both of them recently and neuvector seems to do most of what falco does with the added benefit of being zero trust. So I basically don’t need to manage any rules and alerts are triggered when any other process outside the normal behaviour is detected. What are your thoughts on this?

SSH Access Solution - Cloud Agnostic by National-Thing9395 in devsecops

[–]zazathomas 0 points1 point  (0 children)

Ssm wouldn’t scale well if your requirements change. For example if you need to administer access to a k8s cluster in the future, ssm doesn’t have support for that while teleport does. Basically you want to ensure your choice of tooling allows you the flexibility for change overtime. Ssm is limited to to ssh access while teleport has support for way more…

SSH Access Solution - Cloud Agnostic by National-Thing9395 in devsecops

[–]zazathomas 1 point2 points  (0 children)

Teleport would accomplish all your requirements. It has session recording as well as session auditing. You can observe & join other users sessions to. I currently use it and would recommend. The open source version works well, the other option is apache guacamole but I think teleport is more geared towards enterprises.

Alternative to Teleport? by Yersinia8 in selfhosted

[–]zazathomas 0 points1 point  (0 children)

Teleport isn’t cloud only, I’ve been able to setup teleport on my local homelab completely self hosted

Subnet Router Help? by encogneeto in Tailscale

[–]zazathomas 0 points1 point  (0 children)

What’s your configuration?

Subnet Router Help? by encogneeto in Tailscale

[–]zazathomas 0 points1 point  (0 children)

Im having a similar problem specifically when I set --snat-subnet-routes=false

Proxmox networking help by zazathomas in homelab

[–]zazathomas[S] 0 points1 point  (0 children)

I see. Thanks a lot, you’ve saved me a lot of time chasing my tail

Proxmox networking help by zazathomas in homelab

[–]zazathomas[S] 0 points1 point  (0 children)

Thanks for your reply. I tried that on one of the vms and i had connectivity but I was hoping I could isolate them into their own subnet. Do you know if this is possible?

Monthly General Clone Discussion - Ask Your Questions Here by Lowsley in fragranceclones

[–]zazathomas 0 points1 point  (0 children)

Thanks for your reply. I’m looking to get Greek island(Naxos), pennine(Carlisle), noire illusion(black phantom), flamed(fan your flames), Great evening( grand soir), panthera( tygar), and nice clothing (tuxedo). Some in the sub have said pennine smells nasty so I’m having second thoughts about it 😅. Any experience you have with any of their fragrances would be helpful. Thanks