Inlets Pro - Developer Controlled SDN or is it DevOps

12:56 · Watch on YouTube ↗

Transcript 2,193 words · about 15 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

hey how's it going keith townsend and i have my friend alex ellis again and we're going to talk about something that's really i don't want to call it niche because when he first came to me with the concepts of inlets and inlets pro i kind of thought to myself that's a nightmare i don't i would never want that from a uh network administrator network security perspective but alex has poured a lot of time and energy into the product project and now product that i thought it'd

be willing to share alex first what is inlets in inlets pro well i guess um people probably quite curious now that you said you'd never want that from a network perspective a security perspective and what is the reason you wouldn't want that because i because you're a developer and i don't want developers doing anything with networking like that i want to control i'm a traditional i.t person and uh i want to control my virtual four walls of my data center and inlets lets developers bypass those

four walls however i thought of it as a solution that developers brought but developers really don't do this sort of thing operational this is more of an operational tool than i think it is a developer tool yeah and i think i think you're right there so why would you be worried about inlets and what does it do it creates a network connection from a computer inside a private network to a computer on a public network at which point you can then send traffic to that public

network or ip address and it will be routed to the private one and it can penetrate most corporate network conditions and it can work behind captive firewall you can go into a cafe um order your starbucks let's say deploy openvas or some other kubernetes application and have an ip address on the internet that anyone can access you can then go home and plug that in on your home network on your wi-fi and it will still be up with the same ip address the same link and

that's quite powerful it's not the first time that we've seen it done um there are other solutions like ngrok which is a sas product it's quite limited um in what you can get even if you pay there's argo tunnel from cloudflare if you're a cloudflare customer with your domain registered with them and your dns managed by them but if you're not you know you can't really use it and so inlets was this thing that i put together because i needed to self-host it i needed to

be able to access it behind corporate conditions and for things that were part of our development workflow but you're right since then it's actually taken on more of a sort of i guess service mesh type use case where we're looking at a i t administrator like a keith townsend with his own data center where he was hosted in qts in chicago in chicago who perhaps doesn't have any public ip addresses or ingress or perhaps is running an enterprise application like an old vsphere server and you

want some way of securely tunneling that api to an amazon eks cluster in a region in chicago so that you can run kubernetes applications that automate and talk to that as an on-premises vsphere api so the way that i do that today is that i have a firewall i have a direct connect between my data center and aws i pay uh 800 a month for that port also pay an additional thousand dollars for my internet connectivity uh and then i pay aws uh direct connect charges

for the actual direct connect report so this the use case if it was just this thing that i was using that connectivity for would cost me roughly about twenty one hundred dollars a month so how does so this sounds like what if i can just leverage just my internet connection and if i only had the not even this i could because i can do more than one endless tunnel if i wanted to do uh from a vm into a uh into aws service itself i could

do that because you mentioned service mesh i wrote this blog post and me and you talked about it uh almost a couple of years ago in which i had this scenario and i wrote this up and i kind of had a hashicorp type service message solution to the problem using console was what if i had a lambda function and i wanted that lambda function to talk to a vm in my data center but i only wanted to limit that that activity in that session but my

firewall logic doesn't allow for that to happen because lambda is is a headless service does this help to solve that problem i mean to some degree it can i mean in your specific use case you want a lambda function to talk to let's say that let's say it was a windows vm running on premises running ms sql and you had a lot of data in there and you just can't migrate it but you need to run a weekly report maybe you run it from the lambda

function and push it into s3 when it's done um if you run um lambda in a vpc you could run an ec2 instance in the vpc as well and then you could run an in-last tunnel there and have it connected up and they'll be able to talk to each other now the other use case is not so much what we're talking about here this hybrid cloud for service providers uh sorry for enterprise companies it's more for service providers so let's say you're a code fresh type

service you're providing ci cd on a public cloud it's a complete sas there's nothing that customers can run but then you need them to start running a a bit of software so that you can punch in and you can run i don't know jobs on their existing servers again this is where it becomes interesting is that even though you've got no way of getting into their network if you use inlets and that's pro you can dial back into the control plane and access those private servers

from that public control plane so i can as a service provider i could use this as a call home feature so if i'm managing a storage array some control plane inside of a private data center and i want to send log files back securely back to a centralized service i could use that i can use inlets pro to do exactly that you could but where it where it becomes more interesting i think is where there's a control plane that wants to manage and in an update

state inside a private cluster somewhere there's a company you see them on the inlet homepage called vision and they work with a lot of regulated customers in switzerland so talking banks and they can't have their openshift api public would just wouldn't make sense right but they want vision to be able to provide a management for their openshift clusters to dial in check their health adjust settings do upgrades they do that by running a number of inlet server processes on their sas and then they configure the

customer's site to use an index client and dial back from that literally i could use this to create a managed service around managing my vmware host so yeah if i wanted you know the if i wanted someone outside of my organization to manage vmware host or if i wanted to build a service and this is from the let me switch my hats and put on a service provider perspective and i wanted a universal way to manage a hundred different customers vmware vcenter uh environments this is

a packaged way in order to do that repeatedly i'm not creating snowflake vpn uh sessions hey you know what customer a b or c send me your vp send me what uh vpn concentrator you have let's establish it yeah let's establish rules etc this is a set uh set of rules or controls that are easily deployed and easily audible frankly yeah i mean effectively it's a it's a kind of sd1 right sd1 lite is a good way of looking in lats and inlets pro now the

open source version um needs you to go and add tls to its websocket and it needs you to only use http traffic like rest apis but the pro edition automates the public key infrastructure for that it adds the tls encryption um and it also um gives you the ability to do tcp traffic so level four i've got a database and i want to talk to it i've got a medical protocol that doesn't have any encryption but i need to punch it across to this other network

to orchestrate it and that's the kind of thing that you can do so okay i'm hearing the open source version which is you know it's the endless project then there's a pro service so i have to ask the question how much does this cost because i'm a service provider and i'm i'm really interested in this or i have this use case it's the cto advisor and i just want this i want to get rid of this direct connect cost because functionally i don't need this big

heavy overhead i just need point solutions how much is this costing me i think this goes back to the question of um is kubernetes right for us and again i'd want to spend some time and see if if inlets was the right solution or inlets pro there was a company i did a proof of concept with and we got sort of so far into it and realized that they needed a feature that we were never going to add to the project right and not just for

them and so i advise someone an alternative solution and that's the benefit of actually having an expert that you can speak to about solution rather than just being sold something being on your own um there's three tiers there's a personal tier um for people that want to play around the raspberry pi cluster we'll run kubernetes on their laptop there's a small business tier that comes with five tunnels and commercial support an enterprise tier where we can sort of work out what fits your budget and your

needs and has some additional management around it as well now here's something that's interesting the open source version can benefit from a paid control plane so whilst we're looking at inlets and ns pro is two different proxies with two different capabilities you can take the free version and automate it and you could spend three months writing the code to do that and maintaining it in your team and think about what that will cost you or you can come and get that from us from the vendor

where we're constantly updating it adding features to it and so you can use the free version that will effectively scales very well on a price basis and then have that management control plane as something that's supported and built for you has a rest api it could potentially scale your tunnels to zero when they're not in use and that's where i think sort of an interesting model right you can have an open tunnel you have a closed tunnel you can build your own management control plane for

either or you can come and get one from us so speaking of coming get one from you how do we find the project in the product yes simply inlet.dev that's it or search for in lats online and um there's lots of documentation there's blog posts there's videos there's a community there's slack around this as well so you're not just paying let's say if you bought your personal license certain amount of money per month just to get a tunnel you pay for all those other things you're

paying for the open source automation that can set you up an exit server in two seconds on amazon or 20 seconds on digital ocean or wherever it may be it's a whole package well alex thanks again for joining the program where can people find you online alex alice io he's probably the best place to go and then you've got all of my other links from there twitter linkedin the works all right that's it for this episode of the cto advise you to find me online i'm

at ctoadvisor on twitter that is the best place to interact directly with me dms are open you want to find the company's website is the ctoadvisor.com talk to you next cto does