ziti-doc
ziti
ziti-doc | ziti | |
---|---|---|
23 | 84 | |
34 | 2,071 | |
- | 10.3% | |
9.5 | 9.8 | |
6 days ago | 6 days ago | |
HTML | Go | |
Apache License 2.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
ziti-doc
-
OpenZiti - *everything* you need to implement your own secure, zero trust overlay network
OpenZiti vs BoringProxy has some similarities for sure. The simplest OpenZiti deployment is similar to a boring proxy deployment. The main differences will be that the listening ports "on the network" are going to be from the OpenZiti edge-router which will authenticate before allowing any connection using a strong x509 identity (not a token) and then after that the same identity can be authorized to access one or more services. That's one killer difference to me. There are lots of other things OpenZiti is doing that boringproxy isn't trying to as well. I filed an issue to do a comparison to that some day https://github.com/openziti/ziti-doc/issues/176 thanks for the idea! :)
-
Site-to-Site IPsec VPN with dynamic public address at remote site
Use our open source solution, OpenZiti, and host/manage it all yourself - https://openziti.github.io/
-
Extrovert Wednesday - Telling the World about OpenZiti
You can definitely read more about what OpenZiti is over on the docs page if you're looking for more info about the project https://openziti.github.io/
-
How bad it is ? Security of self-hosted server
If you're interested in it, you can find it over at github - https://openziti.github.io. It's one more thing to setup and maintain so maybe that's a dealbreaker but since this is selfhosted - maybe not ;)
-
How to setup OpenZiti on an OpenWRT device as an alternative to VPNs / private APNs
If you want to go fully open source and self-hosted, use an OpenZiti quickstart - https://openziti.github.io/ - while ignoring steps 1, 2, 3, and 5 ... i.e., step 4 is where you deploy an OpenZiti tunneler on an OpenWRT box.
-
Alternative to manual IP exposing
I not long ago discovered OpenZiti, and to be honest I fell in love with it. I also have a dinamic IP, and I have even some other cases wheren from my place some IoT devices need to find my laptop wherever I may go (I travel a lot).
-
How we use and Secure SaltStack
https://openziti.github.io/ - gives a good intro
-
Help making an Ansible collections
More details: What I'm trying to do is setup a Zero Trust Host Access on my Kubernetes cluster using OpenZiti. Ziti has 4 binaries (controller, router, tunneler and admin console), configuring all these to work together is kinda complex, that's why I thought about making custom modules.
-
Recommended solution secure that will allow my assistant to access a vm in my Azure environment
Probably overkill for your need, but you can give access to your VM without requiring a bastion or VPN, only outbound ports on a NAT gateway using opensource OpenZiti - https://openziti.github.io/. The user would load a client on their device and get access only the the specific resources you define (IP, DNS, port etc). This also means you don't need to assign the IP of the users home (added benefit they can access when not at home).
-
Gaming on the go: How I game remotely and keep my firewall “Perfect Dark”
Create the identity for the Hosting workstation. You can assign as many attributes as you want. Openziti works with an "attribute-enabled role-based access control (ARBAC) model. So, if you have used hashtags, you’re probably familiarized with it.
ziti
- Show HN: OpenZiti (Apache 2.0, P2P, E2E encrypted, full mesh overlay) is now 1.0
-
Has anyone tried OpenZiti?
If you are not aware of what OpenZiti is, this is the description available on their website:
-
zrok: open-source peer-to-peer sharing (release of 0.4.0)
fwiw, its back up. stars for zrok and ziti (i.e., the parent repo) are super appreciated!
-
Self-Hosted Mesh Network / VPN For User-Friendly LAN Gaming Network?
https://github.com/openziti/ziti (1.2k stars)
-
K3S, Authentik, And Practical Use
Create an AUR package for the ziti binaries
-
Docker-Compose Woes
I ask because I'm going to start with the simplified-docker-compose.yml file instead of the more complicated one for starters
-
Upgrading VPN solutions in a remote working Environment
OpenZiti is the most sophisticated and simple-to-use ZTNA platform on the planet. Allows you to create micro-segmented ZTNA networks by desktop application, web application, device, containers, API, and servers. All data is distributed dynamically across an overlay mesh network focused on routing performance, self-healing, and latency. It has desktop clients on all operating systems, pre-built SSH consoles, and SDKs in different languages to integrate OpenZiti into any product natively. And best of all, it's Open-Source. Seriously, try it, you'll be mind-blowing...
-
An SDK for embedding zero trust networking into Node.JS applications and web servers to improve security.
This repo hosts the OpenZiti SDK for NodeJS, and is designed to help you deliver secure applications over a OpenZiti Network - https://github.com/openziti/ziti-sdk-nodejs.
- Ziti
-
Looking for a "file-ingress"/"file upload" service for arbitary person w/ one time link/email
zrok.io seems fit for this purpose though you'd have to do a little work like combining it with FileGator or similar. Future releases would add this functionality directly, you could just watch the project. It is fundamentally designed for web app & webhook testing. It's built on top of a zero-trust networking overlay technology called openziti.io. There are developer discourse channels to help.
What are some alternatives?
ZeroTier - A Smart Ethernet Switch for Earth
oauth2-proxy - A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.
AdGuard-WireGuard-Unbound-Cloudflare - The ultimate self-hosted network security guide ─ Protection | Privacy | Performance for your network 24/7 Accessible anywhere [Moved to: https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt]
tailscale - The easiest, most secure way to use WireGuard and 2FA.
boundary-reference-architecture - Example reference architecture for a high availability Boundary deployment on AWS.
docker-adguard-unbound-wireguard - This solution is a combination of WireGuard, AdGuard Home, and Unbound in a docker-compose project with the intent of enabling users to quickly and easily create and deploy a personally managed full or split-tunnel WireGuard VPN with ad blocking capabilities (via AdGuard), and DNS caching with additional privacy options (via Unbound).
OPAL - Policy and data administration, distribution, and real-time updates on top of Policy Agents (OPA, Cedar, ...)
Nebula - A scalable overlay networking tool with a focus on performance, simplicity and security
devtron - Tool integration platform for Kubernetes
yggdrasil-go - An experiment in scalable routing as an encrypted IPv6 overlay network
gdg - Grafana Dashboard Manager