TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Gravitational Wormhole: WireGuard for Kubernetes

170 点作者 aberoham大约 6 年前

8 条评论

kevin_nisbet大约 6 年前
Author here. Feel free to reach out if you have questions or thoughts about the project.
评论 #19781607 未加载
评论 #19782433 未加载
评论 #19781797 未加载
评论 #19782306 未加载
评论 #19781893 未加载
评论 #19781721 未加载
sloppycee大约 6 年前
Big warning to readers:<p>If Gravitational asks you to complete an &#x27;engineering challenge&#x27; they are using you for free labour.<p>See: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19784787" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19784787</a>
评论 #19788121 未加载
fulafel大约 6 年前
&gt; If you’re running Kubernetes in a network you don’t fully trust or need to encrypt all pod network traffic between hosts for legacy applications or compliance reasons, Wormhole might be for you<p>Is there a good analysis somewhere about how typical kubernetes setups trust the network and what badness an advesary could do with kubernetes network access? How sound is this default deployment setup from security POV?<p>For example I think DNS is used internally for service discovery, and incoming TLS is often terminated and proxied onwards as HTTP - those could be both MITMed, right?
OJFord大约 6 年前
I thought I understood this, and that it replaced (and no doubt did a better job of) what I&#x27;d already done - WG to get nodes on the same network, CNI on top.<p>But requirement 2 confused me: &gt; A Kubernetes cluster with IPAM enabled (--pod-network-cidr= when using kubeadm based install)<p>So, do node machines need to already be on the same network or not?
评论 #19782683 未加载
leetbulb大约 6 年前
Very cool to see WireGuard being used in a mesh implementation. This reminds me of Weave[0] which has worked well for me. I&#x27;ll definitely be experimenting with Wormhole.<p>[0] <a href="https:&#x2F;&#x2F;www.weave.works&#x2F;oss&#x2F;net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.weave.works&#x2F;oss&#x2F;net&#x2F;</a>
nhoughto大约 6 年前
We were recently discussing creating something like for this, the current set of CNI options is wide but shallow. As mentioned in the article CNI is something you want to be as simple as possible, we’ve had trouble with weave and all it’s complexity. Flannel plus encryption is perfect!
评论 #19784869 未加载
laacz大约 6 年前
Just afraid that time will come, when searching for black hole, neutrinos, gravity will primarily yield these kinds of topics. Not actual ones.
badloginagain大约 6 年前
Doesn&#x27;t Istio provide inter-pod encryption, or am I totally off the reservation here?
评论 #19782952 未加载