@@ -0,0 +1,131 @@
|
||||
import type { Metadata } from "next";
|
||||
|
||||
export const metadata: Metadata = {
|
||||
title: "About",
|
||||
description:
|
||||
"Vantage began as a weekend fix for a lost laptop and grew into a fleet control plane. How it is built, and what it deliberately does not do.",
|
||||
};
|
||||
|
||||
export default function AboutPage() {
|
||||
return (
|
||||
<>
|
||||
<section className="rail band band--open">
|
||||
<span className="tag">About</span>
|
||||
<h1 style={{ fontSize: "var(--s-3)", margin: "0.8rem 0 1.1rem", maxWidth: "20ch" }}>
|
||||
Built for the fleet nobody was given a budget to manage.
|
||||
</h1>
|
||||
|
||||
<div className="split" style={{ marginTop: "2.4rem" }}>
|
||||
<div className="prose">
|
||||
<p>
|
||||
Vantage started as a weekend fix for a bad afternoon. A laptop was lost, and finding every server that
|
||||
trusted its key meant SSHing into each one with a text editor open. The list lived in someone's head.
|
||||
Two of the boxes were not on it.
|
||||
</p>
|
||||
<p>
|
||||
The obvious tools were all heavier than the problem. A configuration management stack to write one file. A
|
||||
bastion host that becomes the thing you now have to keep alive. A certificate authority with a rotation
|
||||
story nobody wanted to own.
|
||||
</p>
|
||||
<p>
|
||||
So it began with one job done properly: hold <code>authorized_keys</code> to a known state. Then the same
|
||||
agent turned out to be the right place to run a deploy script, check whether a service was answering, and
|
||||
open a shell when something was on fire. Each addition had to earn its place by riding the connection that
|
||||
already existed.
|
||||
</p>
|
||||
<p>
|
||||
Today it runs across homelabs, small hosting providers, and agencies who inherit client servers and need
|
||||
to prove who can reach them.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div>
|
||||
<span className="tag">How it is built</span>
|
||||
<div className="specs">
|
||||
<div className="spec">
|
||||
<span className="spec__k">SERVER</span>
|
||||
<div>
|
||||
<h3>Go, MongoDB, Redis</h3>
|
||||
<p>
|
||||
One Go binary serving REST for the interface and gRPC for agents. MongoDB holds everything durable;
|
||||
Redis holds sessions and nothing else.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
<div className="spec">
|
||||
<span className="spec__k">WEB</span>
|
||||
<div>
|
||||
<h3>Next.js</h3>
|
||||
<p>
|
||||
An operations interface, not a brochure: dense tables, live log streams, and state you can read at a
|
||||
glance.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
<div className="spec">
|
||||
<span className="spec__k">AGENT</span>
|
||||
<div>
|
||||
<h3>Go, Linux and Windows</h3>
|
||||
<p>
|
||||
A single static binary under systemd or as a Windows service. No runtime, no dependencies, no
|
||||
package manager involved.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
<div className="spec">
|
||||
<span className="spec__k">CONSOLE</span>
|
||||
<div>
|
||||
<h3>Guacamole</h3>
|
||||
<p>
|
||||
Protocol handling is a solved problem. We proxy the connection and manage the credentials around it.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<section className="rail band">
|
||||
<span className="tag">Security posture</span>
|
||||
<h2 style={{ fontSize: "var(--s-2)", marginTop: "0.7rem", maxWidth: "24ch" }}>
|
||||
The parts worth being specific about.
|
||||
</h2>
|
||||
<div className="caps">
|
||||
<article className="cap">
|
||||
<span className="cap__k">Tokens</span>
|
||||
<h3>Hashed, never stored plain</h3>
|
||||
<p>
|
||||
Agent tokens and the secrets read token are held as SHA-256 hashes. The plaintext exists on the
|
||||
agent's own disk at 0600 and nowhere else.
|
||||
</p>
|
||||
</article>
|
||||
<article className="cap">
|
||||
<span className="cap__k">At rest</span>
|
||||
<h3>AES-256-GCM</h3>
|
||||
<p>
|
||||
Private keys, passphrases, vault secrets, identity provider secrets and console credentials are encrypted
|
||||
with a key held only by your deployment.
|
||||
</p>
|
||||
</article>
|
||||
<article className="cap">
|
||||
<span className="cap__k">One-time</span>
|
||||
<h3>Tokens that expire and spend</h3>
|
||||
<p>
|
||||
Pre-registration tokens last an hour and work once. Console session tokens are consumed the moment the
|
||||
tunnel opens.
|
||||
</p>
|
||||
</article>
|
||||
<article className="cap">
|
||||
<span className="cap__k">Recorded</span>
|
||||
<h3>Every mutation is audited</h3>
|
||||
<p>
|
||||
Assignments, revocations, runs, console sessions, secret reveals and settings changes are attributed and
|
||||
kept.
|
||||
</p>
|
||||
</article>
|
||||
</div>
|
||||
</section>
|
||||
</>
|
||||
);
|
||||
}
|
||||
Reference in New Issue
Block a user