I'm flattered that more folks are realizing they want fast/reactive systems like #mgmtconfig but I'd also appreciate a little shout out if you're going to try to copy or be inspired by my ideas.
I know cfengine is mostly legacy these days, but it's still a Goliath compared to the little David that I am.
https://docs.cfengine.com/docs/lts/reference/components/cf-reactor/
#mgmtconfig
3 posts · Last used 10d
Here's a demo of the #mgmtconfig wireguard module.
No central secret store required, private keys never leave the machine, and rotation happens in under 1000ms.
https://www.youtube.com/watch?v=Z91TQPbJ-SU
(I've showed this privately, and now I've got a public live demo! Feedback welcome please! If you or your company is interested in this, please reach out.)
mgmt wireguard module
A friend of mine, Dave Kempe, has kicked off the shorewall-nft project, to continue the legacy of the brilliant iptables frontend (really an API/spec) that Tom Eastep started over 25+ years ago.
https://github.com/sol1/shorewall-nft
There's no better way to do Linux firewalling, and I'll be migrating all of my projects to this.
Yes there's even an #mgmtconfig shorewall module: https://github.com/purpleidea/mgmt/tree/master/modules/shorewall
You've seen all posts
