Skip to content
Notifications
Clear all

Best ZTNA for a hybrid cloud environment with Azure and GCP

1 Posts
1 Users
0 Reactions
22 Views
(@david_chen_data)
Honorable Member
Joined: 6 months ago
Posts: 401
Topic starter   [#19165]

I've been tasked with evaluating Zero Trust Network Access (ZTNA) solutions for a new architecture we're building, which involves a hybrid cloud environment split between Microsoft Azure and Google Cloud Platform. The primary use case is securing access to data pipeline components—including orchestration servers (Airflow), monitoring dashboards (Grafana), and some internal BI tooling—for a distributed team of data engineers and analysts. After a preliminary review of several vendors, Twingate appears to be a strong contender. However, I'm seeking concrete, production-tested feedback from this community, particularly from those managing similar multi-cloud data infrastructure.

Our core technical requirements are as follows:
* **Provider-Agnostic Connectivity:** The solution must seamlessly connect resources in Azure Virtual Networks and GCP VPCs without requiring a mesh VPN between the clouds. Native integration or lightweight connectors for both platforms are essential.
* **Fine-Grained Access Control:** We need to move beyond IP allow-listing. Access policies must be capable of specifying user-to-application rules, ideally integrating with our existing Azure AD for identity.
* **Performance & Reliability Impact:** Since this will sit in the critical path for pipeline management and incident response, latency and uptime are paramount. Any noticeable overhead on connections to, for example, a Cloud SQL or BigQuery instance would be a significant concern.
* **Operational Simplicity:** The administrative burden on the data platform team must be minimal. We prefer a solution where client configuration is automated and network changes don't require re-issuing credentials to the entire team.

Specifically regarding Twingate, I am interested in real-world benchmarks and pitfalls:
* How does the Twingate Connector perform when deployed in both Azure and GCP? Are there any hidden costs related to egress or compute for these connectors?
* How granular can access policies get? Can I define a policy like "Only members of Azure AD group `data-engineering-prod` can reach TCP 5432 on the production Postgres instance in GCP, and only from their corporate-managed device"?
* Has anyone experienced issues with TCP/UDP port forwarding or specific application protocols common in data workloads (e.g., SSH, database protocols, HTTP/2)?
* How does the solution handle failover and high availability across two cloud providers?

I plan to run a proof-of-concept next quarter. Any detailed insights, especially comparative analyses against other ZTNA tools like Zscaler, Tailscale, or Cloudflare Tunnel in a similar context, would be invaluable. I will be sure to publish our own latency benchmarks and Terraform module findings here once the POC is complete.

--DC


data is the product


   
Quote