Posted on 04-20-2017 05:00 AM
Anyone hosting (or considering hosting) their Jamf infrastructure on GCP? Seems similar to doing it on AWS, and for G Suite customers it might be a natural fit.
Posted on 04-20-2017 05:55 AM
No I haven't but two things I've thoughts that come to mind. If I am going to move the JSS itself to the cloud, I figure I'll start by working with Jamf first simply because I don't believe it costs a lot extra, only a migration instance.
That being said, I'm not here to wave the flag so to speak. I did want to point out that I've been hosting our off-campus DP on Microsoft's Azure for a week or so now and it seems to be doing it's job well...granted I'm doing traditional SMB file distribution point, but I'm guessing we could easily add http download support...haven't tried yet. Another possibility we thought about Azure is go Linux and do a JDS out in the cloud...I vetoed that for other unrelated reasons, but I'm seeing that DPs in the cloud work fairly well so long as the right ports are open on the server. I'm guessing GCP will be similar but I don't know what kind of OS you would get on it...guessing some flavor of Linux which is fine with me, but my colleagues tend to be Microsofties predominantly.
Posted on 04-20-2017 07:43 AM
@blackholemac Are you not concerned with any of the vulnerabilities may exist with exposing SMB to the WAN? Http seems like the obvious choice here, but I'm curious what your reasoning is.
Posted on 04-20-2017 08:12 AM
I do have some concerns about security... in short this is an experimental share ... we have the firewall ratcheted up to the max on it ... only used as a back up DP...in the creds used are not AD based... we also are using a slightly nonstandard port for SMB... this alone is probably not secure enough but what sparked us to try it is that we use Azure internally for other SMB shares and it works really well and our security guys seem fine with that. Long term I want to switch to http primarily to allow resumable downloads but it will probably help me tighten up security as well .