one: Is this documented somewhere? I use zeromq for the (internal, but by design usually accessible on the public internet) API of my project
two: what happened to zero trust? Every network is untrusted.
one: Is this documented somewhere? I use zeromq for the (internal, but by design usually accessible on the public internet) API of my project
two: what happened to zero trust? Every network is untrusted.
I've never dropped a piece of software as quickly as that.
Security is hard, and proxies/VPNs are cheap.
Do you have any specific reasons why this is a bad idea? Especially if it's been secured, as the article implies it was.
The other side of this is that while Pieter's writing was marketing genius, it was also woefully understating the complexity of any practical use case. The way I tried to summarize that to folks who were keen to try zeromq then was that they should start at the back of the book with the most complex example, and that's by far the simplest setup that they could hope to end up with once they start thinking about putting something into production. And everything leading up to that - a book no less - was exclusively educational/toy use cases.
Your API can be accessible obviously, but put ZeroMQ behind a firewall so only the API server can reach it.
If it’s running on the same server, at least block the port ZeroMQ is listening on from the outside world.
There are easier ways to achieve that than kubernetes with sidecar mesh.