Maybe the external ingress node can be a load balancer controlled by the k8 cluster. But then you still have to communicate with the home server and it has no exposed ip address
How so? You can just rent a cheap server to tunnel through, while having the benefits of your home machine(s) for compute.
> Maybe the external ingress node can be a load balancer controlled by the k8 cluster. But then you still have to communicate with the home server and it has no exposed ip address
Do you mean that you wouldn’t be able to access the K8s control plane endpoint then (which you could if configured properly)? Or something else?
SPOF
(@'ing because we reached the maximum reply limit)
Or just get your very own static IP.
It's a ZPOF.
Routing happens automatically on nearby router routes
It's deep down a matter of taste, you have a home server in Arizona and you route users to a Hetzner server in Germany and then back?
Don't justify, just recognize it's in bad taste, seek to use ip addresses as geographical host identifiers. Do not hide origin or destination. Minimize
Sarcasm obviously, but it's a fun exercise, especially if you get a real (v6, probably) net to announce.
Kidding about building your own AnyCast network (although you really could…), but he.net tunnel broker is GOAT.
There's your problem. You need some form of cost attached to some identity assets, anything under the IANA umbrella, ips/domain names. This is in order to prevent sybil attacks. This is all well studied under he hashcash bitcoin era as PoW.
So yeah, you actually need to spend some money not in exchange of something here, but as the very thing you need, you need to distinguish yourself from those that spend 0$, not because they are cheap, but because they may do it 1000 times and ruin it your pooled reputation.
can you describe a bit more? I cannot connect the dots here on how terabytes are tied to free v6 tunnel - likely I'm missing some details. Thank you in advance.
My Unifi Cloud Gateway Max doesn't (yet) support BGP, but other Unifi devices do, so I do hope that it'll come to my device to. If not, I'll have to think of other ways to test it. But in the meantime, there's plenty of other stuffs to learn.
I have a real, ISP-routed IPv6 net to play with.