01 · Zero-trust networking
Secure access to every remote site, nothing on the public internet
Every remote site joins a private WireGuard/VyOS mesh back to AWS. Teleport checks identity per app, and Cloudflare WARP sits in front as another wall, so operators reach routers, hubs and robot controls without anything being exposed.
- ›Automated peer registration with a REST integration layer on ECS
- ›Domain-based split tunneling with dnsmasq, ipset and iptables policy routing
- ›Highly available Teleport giving per-app, identity-based access to router, switch, Zigbee hub and robot UIs
- ›Wrote a retry patch for Teleport’s app tunnel client, prepared for upstream
- ›Cloudflare tunnels, virtual networks and Mesh, all as Terraform modules
// toggle a layer, watch who gets through
engineer (enrolled, MFA) → robot-ui.node-17
attacker (stolen password) → robot-ui.node-17
Blocked at Cloudflare WARP. Two more walls behind it.