Skip to content

[Feature] Optional VPN to connect to container #160

Description

@Cameronsplaze

Is your feature request related to a problem? Please describe.

Two main problems:

  • When I was looking at Jellyfin, I noticed https might be a lot of work. However, wrapping http in a vpn tunnel might be a fast/secure workaround to make sure it's encrypted. (And other similar situations).
  • If the leaf-stack contains all of your family's photos growing up, the leaf-stack is on the open internet. You'd want a second layer of security between the two. I.e the VPN will block connections without exposing the container, which may have security flaws.

Describe the solution you'd like

Needs to support most clients, like OpenVPN / WireGuard / etc.

Possible paths (If associate_client_vpn_target_network/disassociate_client_vpn_target_network works out, that's my favorite so far):

  • AWS VPN (Client, NOT site-to-site):
    • Very expensive (for the scope of this project). $0.10/hr => $72/month (AWS Client VPN endpoint association) regardless of if it's in use.
    • If you can manage AWS Client VPN endpoint association in boto3, could maybe be apart of the start/stop system stack? We need to minimize the 24/7 cost as much as we can. Maybe these two are enough? Then we wouldn't even have to re-define the VPN constantly:
    • Could tie to the BaseStack, so cost would only be once. Would want to re-design maturities, and/or add a second "key" that describes the base-stack-id you're adding a leaf-stack to.
  • Maybe there's something we can install into the Ec2 instead? This way, it's only active when the container is up and some one is connected? The host/container port CAN be different in the CDK (so we can separate them in the config if we need), I just don't know if there's an easy way to intercept the connection or not.

Describe alternatives you've considered

N/A

Acknowledgements

  • I may be able to implement this feature request
  • This feature might incur a breaking change

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions