Is your feature request related to a problem? Please describe.
Two main problems:
- When I was looking at Jellyfin, I noticed https might be a lot of work. However, wrapping http in a vpn tunnel might be a fast/secure workaround to make sure it's encrypted. (And other similar situations).
- If the leaf-stack contains all of your family's photos growing up, the leaf-stack is on the open internet. You'd want a second layer of security between the two. I.e the VPN will block connections without exposing the container, which may have security flaws.
Describe the solution you'd like
Needs to support most clients, like OpenVPN / WireGuard / etc.
Possible paths (If associate_client_vpn_target_network/disassociate_client_vpn_target_network works out, that's my favorite so far):
- AWS VPN (Client, NOT site-to-site):
- Very expensive (for the scope of this project).
$0.10/hr => $72/month (AWS Client VPN endpoint association) regardless of if it's in use.
- If you can manage
AWS Client VPN endpoint association in boto3, could maybe be apart of the start/stop system stack? We need to minimize the 24/7 cost as much as we can. Maybe these two are enough? Then we wouldn't even have to re-define the VPN constantly:
- Could tie to the BaseStack, so cost would only be once. Would want to re-design maturities, and/or add a second "key" that describes the base-stack-id you're adding a leaf-stack to.
- Maybe there's something we can install into the Ec2 instead? This way, it's only active when the container is up and some one is connected? The host/container port CAN be different in the CDK (so we can separate them in the config if we need), I just don't know if there's an easy way to intercept the connection or not.
Describe alternatives you've considered
N/A
Acknowledgements
Is your feature request related to a problem? Please describe.
Two main problems:
Describe the solution you'd like
Needs to support most clients, like OpenVPN / WireGuard / etc.
Possible paths (If
associate_client_vpn_target_network/disassociate_client_vpn_target_networkworks out, that's my favorite so far):$0.10/hr=>$72/month(AWS Client VPN endpoint association) regardless of if it's in use.AWS Client VPN endpoint associationinboto3, could maybe be apart of the start/stop system stack? We need to minimize the 24/7 cost as much as we can. Maybe these two are enough? Then we wouldn't even have to re-define the VPN constantly:Describe alternatives you've considered
N/A
Acknowledgements