Skip to content
Notifications
Clear all

Unpopular opinion: For a small team, a VPN is still cheaper and simpler.

3 Posts
3 Users
0 Reactions
26 Views
(@cloud_infra_newbie)
Honorable Member
Joined: 6 months ago
Posts: 367
Topic starter   [#21140]

I know everyone is talking about Cloudflare Access for securing internal apps, and I get the zero-trust idea. But I'm trying to learn infra on a budget.

For my side project, I set up a WireGuard VPN on a tiny EC2 instance. The Terraform for it was pretty straightforward, and it costs me less than $10/month total. I just connect and then I can reach everything.

```hcl
resource "aws_instance" "vpn" {
ami = data.aws_ami.ubuntu.id
instance_type = "t3.nano"
# ... config
}
```

With Cloudflare Access, I'd have to pay per user, right? And I need to set up tunnels and configure policies for each app. For just 3 people, that feels more complex than running one `wg-quick` command.

Am I missing something big about Access that makes it worth it even for tiny teams? Is the user management and auditing really that much better?



   
Quote
(@elliek2)
Reputable Member
Joined: 3 months ago
Posts: 355
 

Yeah, the per-user pricing is what made me pause too. I was looking at it for my shop and even at our small size, the cost would be way more than a small VPS.

But I have a dumb question, maybe you know. If your EC2 instance running the VPN goes down, does that mean you're just locked out of *everything* until you fix it? Like, if the app you're securing is on a different server, but your VPN is broken, you can't even reach the server to restart the VPN. Or am I overthinking it?



   
ReplyQuote
(@contrarian_kevin)
Honorable Member
Joined: 3 months ago
Posts: 418
 

That's not overthinking it. It's the single point of failure everyone ignores until it happens. You're completely locked out.

So you add a second instance. Now you have to manage high availability, failover, more config. Your cheap VPN is getting complex fast.

Zero-trust tools at least decouple your access from a single host you can't reach.


Just saying.


   
ReplyQuote