fabio
wesher
Our great sponsors
fabio | wesher | |
---|---|---|
7 | 10 | |
7,252 | 888 | |
0.2% | - | |
0.0 | 5.8 | |
about 1 month ago | 7 days ago | |
Go | Go | |
MIT License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
fabio
-
Replicating and Load Balancing Go Applications in Docker Containers with Consul and Fabio
After some research and testing, I landed on using Consul and Fabio as the demo infrastructure. Of course, there is a myriad of other options to accomplish this task, but because of the low configuration and ease of use, I was impressed with this pairing. Both projects are mature and well-supported, and very flexible--just because you can run them with low configuration, doesn't mean you have to. I wanted to keep this demo constrained, but the exercise did get me excited about exploring things further: circuit breakers, traffic splitting, and more complex service meshes.
-
Why TLS is better without STARTTLS (2021)
Sniffing the SNI from the underlying TCP connection is the proper way to do this.
a couple examples I know of(only know go ones of the top of my head):
https://github.com/fabiolb/fabio/blob/master/proxy/tcp/tls_c...
- Deploy without interrupting clients is hard.
-
HashiCorp Consul: What's the catch?
HAProxy, Traefik, FabioLB, gobetween, and F5 BIG-IP also support native integrations with Consul for service discovery / service mesh.
-
My favorite hosting stack: Consul, Nomad and Vault on Digital Ocean
Check out https://github.com/fabiolb/fabio instead of traefik, it's 100x simpler and "just works". Traefik... I don't like traefik. Fabio is as simpler than traefik in the same way that the hashistack is simpler than k8s.
-
internal naming conventionds
I use Hashicorp Consul and Hashicorp Nomad for service discovery and task scheduling respectively, with wesher for my internal private management network that Consul, Nomad, etc run on to protect the management interfaces. Fabio bridges the gap between the wesher wireguard VPN and the rest of my home network.
-
Using Traefik on Nomad
How do you feel about using Fabio (https://github.com/fabiolb/fabio) - in addition to/or replacement for traefik?
wesher
-
Would we still create Nebula today?
https://github.com/costela/wesher
Wiresmith: Rust, auto-configs clients into a mesh
-
Does a fully featured WireGuard-protocol based corporate VPN software exist?
Maybe take a look at Wesher https://github.com/costela/wesher
-
Mesh of multiple wg tunnels
I run a Wireguard mesh network with Wesher, and I am pretty sure that there are other projects to automate this. Is there a reason not to use them?
-
Tailscale/golink: A private shortlink service for tailnets
From a purely networking perspective, there are far better solutions than tailscale.
Have a look at full mesh VPNs like:
https://github.com/cjdelisle/cjdns
https://github.com/yggdrasil-network/yggdrasil-go
https://github.com/gsliepen/tinc
https://github.com/costela/wesher
These build actual mesh networks where every node is equal and can serve as a router for other nodes to resolve difficult network topologies (where some nodes might not be connected to the internet, but do have connections to other nodes with an internet connection).
Sending data through multiple routers is also possible. They also deal with nodes disappearing and change routes accordingly.
tailscale (and similar solutions like netbird) still use a bunch of "proxy servers" for that. You can set them up on intermediate nodes, but that have to be dealt with manually (and you get two kinds of nodes).
- Wie würdet ihr derzeit ein persistentes VPN-"Mesh" für ~20 Geräte bauen?
-
How to add new client to wireguard in VPS without getting public IP changed on the client?
There are two factors at play here. The client's public IP actually depends on the gateway they use on accessing the internet. You can disable routing and your clients will keep their public IP and general internet access won't go through the VPS. However, if you want the traffic between "clients" also skip the VPS, then you want a mesh network. wesher and wg-meshconf can help you on configuring them.
-
Anyone using WireGuard for production as SDN?
Have you considered https://github.com/costela/wesher or does this not fit your use case?
-
internal naming conventionds
I use Hashicorp Consul and Hashicorp Nomad for service discovery and task scheduling respectively, with wesher for my internal private management network that Consul, Nomad, etc run on to protect the management interfaces. Fabio bridges the gap between the wesher wireguard VPN and the rest of my home network.
-
Building a Mesh VPN Tool for the Community
How does your solution compare to wesher?
-
Wireguard Mesh Network Options
How does it compare to https://github.com/costela/wesher?
What are some alternatives?
envoy - Cloud-native high-performance edge/middle/service proxy
wg-meshconf - WireGuard full mesh configuration generator.
gobetween - :cloud: Modern & minimalistic load balancer for the Сloud era
ergo - An actor-based Framework with network transparency for creating event-driven architecture in Golang. Inspired by Erlang. Zero dependencies.
git2consul - Mirrors the contents of a git repository into Consul KVs.
wireguard-vanity-keygen - WireGuard vanity key generator
b3lb - BigBlueButton Load Balancer
wiresteward - Wireguard peer manager
vkv - vkv enables you to list, compare, move, import, document, backup & encrypt secrets from a HashiCorp Vault KV engine
kilo - Kilo is a multi-cloud network overlay built on WireGuard and designed for Kubernetes (k8s + wg = kg)
gateway - A federated api gateway for graphql services. https://gateway.nautilus.dev/
drago - ☁️ Securely connect anything with WireGuard® and manage all your networks from a single place.