Similarly how does authorization/authentication/encryption work between the host and the forked of work? How is this all secured with minimal permissions?
Similarly how does authorization/authentication/encryption work between the host and the forked of work? How is this all secured with minimal permissions?
On fly.io you get a private network between machines so comms are already secure. For machines outside of fly.io it’s technically possible to connect them using something like Tailscale, but that isn’t the happy path.
> how do I make sure that the unit of work has the right IAM
As shown in the demo, you can customise what gets loaded on boot - I can imagine that you’d use specific creds for services as part of that boot process based on the node’s role.
I still feel like Kubernetes might be the most profitable thing to ever happen to AWS for the same reason--and not because of EKS (their hosted Kubernetes control plane).