openmainframeproject / tac

Open Mainframe Project TAC processes and meeting notes
https://tac.openmainframeproject.org
Apache License 2.0
69 stars 33 forks source link

Secure access to OMP #550

Closed v1gnesh closed 11 months ago

v1gnesh commented 1 year ago

Ideally, before users/projects are onboarded to the infra, a plan for secure access needs to be in place.

For Linux on Z at least, I see this as an opportunity to use new tech, and to work more with startups.

Continuing what's mentioned here... Tailscale is a zero-hassle solution on top of a very light-weight and performant VPN technology that's built for today - WireGuard.

Tailscale supports workflows related to SSH and makes it as easy as peasy to work with SSH targets from VS Code (for example). VS Code supports SSH & remote developement already, sure; but with Tailscale, it's seamless. https://tailscale.com/blog/machine-explorer-vscode-extension/

Sure, the choices are limited based on who's involved, what's currently in use, etc. As a Z enthusiast, I strongly suggest that this tech is reviewed. In my view, mainframe / IBM should take every opportunity to demonstrate new tech on Z. They are chances to show both the strengths of the platform & boost startups whose tech pairs well with scale-up.

This needn't be recurring item or even on the call; just something that would be nice if it happened. Note that WireGuard will very likely be the successor to IPSec. So the time investment in WG / Tailscale isn't just for this use case. WG could very well have a future in zOS Comms Server.

jmertic commented 11 months ago

Not sure of an action for the TAC - closing.