Skip to content
Notifications
Clear all

Zscaler ZPA or Akamai Zero Trust for global manufacturing sites

18 Posts
18 Users
0 Reactions
4 Views
(@devops_grunt)
Honorable Member
Joined: 6 months ago
Posts: 566
 

For your three specific worries, they're all tied together. The day-to-day management learning curve is steep because you're learning their specific policy engine and GUI quirks, not zero trust concepts. That's the hidden cost - the ongoing man-hours to keep policies updated as your apps change.

On automation, the Zscaler Terraform provider exists, but it's a leaky abstraction. You'll spend more time handling API throttling and unexpected provider behavior than writing your actual config. I'd budget for a significant amount of scripting just to make your Terraform runs idempotent and resilient, which the vendor won't tell you about during the sales cycle.

For plant worker simplicity, both are fine once deployed. The real issue is the first-mile setup on hundreds of locked-down factory PCs. You'll need a rock-solid, vendor-approved imaging or deployment script, and testing that across your three geographies with different local admin policies will eat up weeks.


Automate everything. Twice.


   
ReplyQuote
(@danm)
Honorable Member
Joined: 3 months ago
Posts: 452
 

Great question. On your third point about automation, I've had my hands dirty with both. The Zscaler Terraform provider is more complete than Akamai's, but that's a double-edged sword. You'll still end up writing wrapper scripts because their APIs throttle hard, which can break a full Terraform apply mid-run.

For plant worker simplicity, the real hurdle is those locked-down factory PCs. Neither vendor's client will install without local admin rights, which most plants lock down tight. You'll need to work with the desktop team to get the client pre-deployed via SCCM or whatever they use. The actual daily use is simple after that.

Hidden costs are the connectors. Don't just size them for steady state. Plan for your biggest shift change when everyone logs in at once. We had to double the VM size at two sites after go-live, which hurt the budget.



   
ReplyQuote
(@alexh99)
Estimable Member
Joined: 3 months ago
Posts: 119
 

That connector sizing hit us too. Vendor docs said one app connector per region, but we found latency spikes during peak logins that only adding more connectors fixed. It wasn't just about VM size, it was about distribution.

Did you see any guidance on how many connectors per user load, or was it all trial and error?



   
ReplyQuote
Page 2 / 2