Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); private-network RFC by farhoud · Pull Request #67 · functionland/docs · GitHub
Skip to content

private-network RFC - #67

Merged
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main
Mar 29, 2022
Merged

private-network RFC#67
gitaaron merged 11 commits into
functionland:mainfrom
farhoud:main

Conversation

@farhoud

Copy link
Copy Markdown
Contributor

No description provided.

@farhoudfarhoud linked an issue Mar 25, 2022 that may be closed by this pull request
Comment threaddocs/RFCs/private-network.md Outdated
- Functionland Issue:

## Background
we are using IPFS as our file system. but IPFS is build to use for public data, and it does not support ACL,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the purpose of building a temporary workaround to auth/ACL instead of just waiting for the auth/ACL to be developed?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
I don't think the security layer that cover all the stories would be ready in at least 3 month. and also i personally can't relay on access control by encryption only to make user safe. with this solution we can demo useful box and photo in in around a week.
As @masih mention i should explain more on public network risk's

@gitaarongitaaronMar 27, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@farhoud thanks for the clarification. I am still not sure where this PR is coming from (probably because I joined the team after this work commenced). Could you please share a few of the use cases / user stories this PR is solving? What I am trying to understand is how this PR will directly impact BOX customers and their capabilities.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this PR is trying to cover two different scenarios -

  1. Private communication between the fula-client and fula-api (eg/ uploading a photo to a BOX and retrieving a photo from a BOX)
  2. Private communication between BOXes or other 'peers' in the fula-network (eg/ data syncing)

Is that correct?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. and i try to add more on it.

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
For box setup user provide an environment variable SECRET which is password he should remember.
the secret then convert to a hash of 256 bit by algorithm like sha256 and generate the swarm.key for ipfs and libp2p node's.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sounds related to the discussion @masih and @ruffiano89 were having around the question -

what is the relationship between DID and PeerId?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to separate them.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think when we can use DID instead of Peer id to connect (verified connection) box <---> box and client <---> box which also most cover internal IPFS like bitsawp engine then that's the end of life for this proposal

like the libp2p gatekeeper should use the DID to let others connect to my box or ... .

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if we want to use ipfs-cluster then it also have to cover a lot of ground on go lang too.

Comment threaddocs/RFCs/private-network.md Outdated
For network discovery its manual process that user should provide all box peer id's in config.

## Scope of work
- human friendly password to swarm.key

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this could be broken into its own doc? The doc would answer the question - what is the user interface that enables us to provide a human friendly password and generate a shared swarm.key at the same time? Once again sounds related to what @ruffiano89 is working on.

@farhoudfarhoudMar 26, 2022

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think by adding the human readable password i make this PR a little bit complicated. but my thinking was asking user to enter a 64 character in web app or photo's is painful task so i suggest to change it to more human readable think.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see any overlapping. we are working at different layer.

@masihmasih left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great start 👍

Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated
Comment threaddocs/RFCs/private-network.md Outdated


## Alternative approaches
- Using VPN for creating the private network

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expand on this please.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gitaaron
Can you collaborate with me on this?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apologies I think I am mistaken on the use case / purpose of this PR. You can remove this.

For Fula client when user call createClient he should also provide the password he used for setting the box's.

For network discovery its manual process that user should provide all box peer id's in config.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal

Comment threaddocs/RFCs/private-network.md Outdated
- fula-client constructor should get another parameter call secret and if exist set connProtector for libp2p
- create an example for the describing functionality

## Implementation

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider providing an overview of steps, where each sub section expands on.

Comment threaddocs/RFCs/private-network.md Outdated
}

```
the box and client already support pkey input, but we should add the above function to them

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Capitalise first letter in paragraphs. I'll stop pointing this out for the rest of the document.

  • Seems like there is a specific place in code you envision this needs to be added? If so, link it up.

Comment threaddocs/RFCs/private-network.md Outdated
the box and client already support pkey input, but we should add the above function to them
and after that we should change existing pkey on both fula and box to use the above function.

for creating an example we can create copy of react-gallery and add the password field in config.<br/>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flesh this out as a case study with more details. Remove <br/>?

farhoudand others added 8 commits March 26, 2022 13:33
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
Co-authored-by: Masih H. Derkani <m@derkani.org>
@farhoud

Copy link
Copy Markdown
ContributorAuthor

@masih@gitaaron
I try to cover all the feed back but i still have to work on implementation and case study. its more of preview can u review it.

@farhoud
farhoud requested review from gitaaron and masihMarch 28, 2022 09:41
@farhoud

Copy link
Copy Markdown
ContributorAuthor

The second draft is ready.

@gitaaron
gitaaron merged commit 50d8f6d into functionland:mainMar 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

design doc: private network

3 participants

@farhoud@gitaaron@masih