Zero-Trust RDP and SSH Access to VMs on Google Cloud
github.com
github.com
Weirdly enough I thought this was the ability to provision a wireguard-esque proxy to any machine you want, operated at the edge of the cloud, but it seems like it's really TCP-over-HTTPS.
It's easy to imagine doing the former (dynamic wireguard proxy surfacing) too though -- wireguard sidecar container with shared network namespace with the workload in question + open-to-the-world port somewhere and you'd theoretically have access to any port you wanted on said machine as well. Feels like an easy set up to trust as wireguard is pretty reliable/sound.
[0]: https://fly.io/blog/ssh-and-user-mode-ip-wireguard/
[1]: https://vadosware.io/post/stuffing-both-ssh-and-https-on-por...
I use a JWT proxy + ghostunnel within GKE with a VIP so it's not quite their reference setup but it's extremely "just works" outside GKE being weird and eating its own routes.
BTW, side-note but try out ghostunnel over stunnel! I've really enjoyed using it and it's been fantastic to debug and work with.
Yeah that's really amazing, with client-side software like they've already made and I've seen from other vendors (whether GUI or TUI) the interfaces IaaS/PaaS companies can build are really slick. Looks like they'll be able to cut down on dashboard fatigue/complexity people are wrangling quite a bit.
> I use a JWT proxy + ghostunnel within GKE with a VIP so it's not quite their reference setup but it's extremely "just works" outside GKE being weird and eating its own routes.
Interesting, so JWT proxy (or any other auth mechanism that is viable over HTTPS) -> ghostunnel machine w/ public VIP -> Target machine ? Or ghostunnel directly running on the Target machine which holds the public VIP? Or does the JWT proxy take the public IP and the ghostunnel machine keep the private VIP?
Apologies just want to be able to picture your solution clearly.
> BTW, side-note but try out ghostunnel over stunnel! I've really enjoyed using it and it's been fantastic to debug and work with.
Thanks for the recommendation of ghostunnel, will use it in the future over stunnel next time I hack together something like this.
BTW: super-side note, breath of fire III avatar was a blast from the past, instantly recognized it.
> Interesting, so JWT proxy (or any other auth mechanism that is viable over HTTPS) -> ghostunnel machine w/ public VIP -> Target machine ? Or ghostunnel directly running on the Target machine which holds the public VIP? Or does the JWT proxy take the public IP and the ghostunnel machine keep the private VIP?
jwt proxy takes in the iap jwt, they give you the audience and it's just parsed, this lives in the same pod as ghostunnel. ghostunnel goes through a NAT to a public dest, where ghostunnel is _also_ running. it has extremely strict TLS requirements (Forced valid CN to be sent/accepted, strict DNS, along with a single purpose CA, cert, and key).
It's like
IAP =inside-gcp=> (JWT proxy -> ghostunnel) =public=> (ghostunnel -> thing)
There's a more modern way to do this, but this works really well and gives absolutely fantastic introspection, is super easy to use it as a public proxy, and allows you to only use minimal APIs in GCP (IAP + GKE, you don't need GKE but you also don't wanna manage all the things it does for you with annotations. :D)
I’d say appearance != usability, and while this might look a bit dated, it probably behaves a lot more like a desktop application than most Electron apps out there.
I don't understand why RDP/SMB/... with plaintext auth over SSL hasn't been a thing for at least a decade, does Microsoft just not care about transport security?
Logging in is via `gcloud compute ssh`. Authenticating `gcloud` involves a corporate login which uses a client certificate and two-step.
For all the components involved, it works pretty well!
Can you encrypt the client private key on disk and use sth like ssh-agent?
----
Also, now that you mention it, even if I encrypted the generated SSH key, wouldn't running a `gcloud ...` command again just ... re-generate the key, in unencrypted form?
When I log in to `gcloud`, that goes through our corporate login. Corporate login uses a client certificate and two-step.
Host myhost
ProxyCommand gcloud compute ssh user@myhost --zone=myzone --tunnel-through-iap --command="nc 0.0.0.0 22" -- -o "UserKnownHostsFile /dev/null" -o "StrictHostKeyChecking no"https://github.com/ockam-network/ockam/tree/develop/document...
Is there a Linux client too?
The cost ended up being around 1€/hr when the instance was on, and 0.06€/day for the storage. I am sure this could be optimized (e.g. use snapshots and spot instance) - but I just couldn't be bothered to. For me it is worth it.
Seems that it would work quite well for turn based games (including auto save)
Stadia, GeForce NOW, Xbox Game Streaming and PlayStation Now: I've tried them all, and GeForce NOW specifically is very good. But, they only allow me to play a subset of my large pre-existing game library, and/or make me buy games again, which I'm not interested in.
Stadia is specially bad at this, having to purchase on a game-by-game basis, not being compatible with any existing ecosystem (Steam, PS, Xbox have cloud saves and friend lists), and then trusting Google to run my game forever on their servers after paying a one-time cost.
It barely worked in their web client but the desktop client worked pretty well.
I'd love to hear about alternative solutions that don't require Windows, and still spit out colour-accurate CMYK indesign files; the printing shops won't accept anything else.
Most printing shops I've had to treat with will also accept PDFs, is that the case? Because then, there's a case to be made for converting your templates to HTML (gives you access to a huge amount of tooling) and printing them to a PDF through a headless browser instance (like pptr.dev). That has worked for me in the past, and is accessible and good quality (though I did not need accurate CMYK, so YMMV).
(Though browser-based PDF isn't a panacea either. We've got one customer whose 250 page technical manual needs between 40 and 70 minutes to generate through paged.js and Chrome… They're fine with running it as an overnight job, but it's still painful to watch.)
As for Windows in general, 90% of the Windows servers I see fall into one of the 2 categories: 1) they run some Windows-only software or 2) the sysadmins at the company know Windows, so that's what they use. If your company relies on something from 1), you're very likely also going to fall into 2).
Specific example: a company wanted to allow any employee to log in from any computer and be ablr to get work done. A VM terminal server was too heavy for their network and server budget and they already had decently powerful PCs, so they went with AD and that roaming accouts thing. They had to hire a Windows server sysadmin to manage it.
When they decided they also needed a good NAS, web server and backup system, they already had a Windows sysadmin on staff and the licences+over-spec required to run in on Win were still cheaper than hiring another sysadmin.
The last time I was assessing Windows remote * for performance, VNC* implementations with a mirror driver provided far better performance than vanilla RDP.
https://github.com/Ylianst/MeshCentral
It has a free instance here
In the beginning they needed AD because business is heavily Windows centric.
Then they started using Windows Server for DNS, business apps, shared volumes, etc...
After I joined I started separating concerns / reducing blast radius and now we use Windows Server for AD and a few apps that are Windows only.
Azure AD + Intune MDM is getting better and I think we will be able to kill our managed AD soonish though.
Additionally lots of enterprise shops, despite what HN crowd thinks, are mostly on Microsoft stacks, so that .NET application is going to connect to other APIs and stuff not available on GNU/Linux.
Then, many companies use VMs as desktops for contractors, you are just not allowed to plug anything on their network, so you are using Visual Studio via RDP/Citrix.
As an example, in life sciences most of the laboratory hardware only has APIs available via COM/.NET Framework.
Less the legacy use-case than how do we integrate everything with everything.
0. http://cloudscaling.com/blog/cloud-computing/the-history-of-...
There is nothing I can learn from accessing a VM in production that I can't learn from my monitoring system.
In prod where I work, if someone logs into a production VM we mark it tainted and replace it with a fresh instance. This keeps things nice and consistent.
Of you need an interactive session on a prod machine you are missing tools.
My rule for that is: more than once a year or more than 6h? Automate and tool it. Less? SSH or other special-case tools are fine.
Other than how to fix gaps and other problems with your monitoring? As you get experience, you’ll learn this is done like a garden — you can heavily reduce your need for interactive sessions but it never goes to zero.
I think you’re making the classic mistake of treating a guideline as more of a religious mandate. Yes, it’s good to have servers be easily replaced but that desire does not magically rewrite all existing software or retrain every IT worker.
Similarly, automation is great but you need to develop and maintain it - which almost always involves interactive work. The taint process you mentioned is a popular way to balance those needs long-term.
Finally, if you are thinking of “server” as only a production-hardened network service you’re missing out on a lot of other things enterprises use cloud services for, such as developer workstations or general virtual desktops. Many places heavily expanded that over the last year because you avoid the security concerns about having your data on easily lost/stolen laptops and can avoid turning your VPN into a massive bottleneck for the entire company.
> In prod where I work, if someone logs into a production VM we mark it tainted and replace it with a fresh instance. This keeps things nice and consistent.
doesn't make sense from an ROI perspective, at a great number of businesses. Like, "this would take a decade to pay off, and that's assuming it requires no maintenance" kind of bad ROI.
Lots of places, you script vm/server configs (even just with bash) and get CI running automated tests on important branches, and you've captured 99% of the benefit available from automation. Would the other stuff be nice? Yes, but five people saving 15 minutes per week means you can't reasonably spend the kind of time on it—for initial set-up and for ongoing maintenance—that you would if it were fifty people saving 15 minutes per week, let alone 500 (at that point you can have a couple people dedicated full-time to just that one piece of automation, and it's still saving you money).
I'd be interested in seeing what credentials in toto are there, and which ones are ephemeral, and susceptibility to lateral traversal.
Could you respond on the merits of the critique?
OS Login defines two IAM roles, one for “Can I log in?” and one for “Can I sudo?”. Those are implemented on the system via PAM, so you can add whatever additional restrictions you’d like.
Fetching of user information via OS Login is implemented via a NSS module. POSIX attributes can be customized via the Google Directory API. And I believe Google Groups can be mapped to POSIX supplemental groups, but I’m not certain.