Skip to content

Evaluate mesh and end-user access options #40

Description

@yannick-vinkesteijn

Feature description

Evaluate the access setup beyond the Headscale operator mesh.

Mesh at review (pinned commit): https://github.com/srdp-hub/srdp/tree/6571735939e43fbf8d44b97a9fb4d25283f6234f/deploy/scaleway/deploy/mesh

Use case

As shipped, end users would need Headscale enrollment just to open Marimo. We want to decide the access profile for researchers and check whether one service can cover both open access and VPN.

Proposed solution

  • Decide the end-user access profile: mesh only, or a browser facing ingress (public LB or identity aware edge). May become an ADR.
  • Evaluate Pangolin as a single service covering both open access and VPN. Check the blockers: OIDC federation to an external IdP (we want Zitadel) may be a paid feature, and community edition limits are unclear. If it works it removes the split DNS and hosts file workarounds in the mesh backlog.
  • Keep Headscale as the default until an alternative clearly wins.

Alternatives considered

Headscale only (current), public ingress in front of oauth2-proxy, Pangolin.

Component: Infra: Other

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions