VMware/Security: Opvizor OpBot, cool, but scary too.
I've posted about OpBot in the past w/ a brief overview on how you can setup and deploy. It's a very cool and immensely useful tool. However, I must balance this with security. Responsibly deployed, it can be a very useful tool. However, there is a dark side to this from a security management perspective. It also poses the very real risk for allowing generic internet access from within your datacenter. First off, OpBot from Opvizor makes it very clear that you should only grant it's integration account read-only access. You can do 'destructive' PowerCLI commands by passing login info via slack, but also not recommended. As much as they have created an immensely useful tool, it also is somewhat of a pandora's box. It's brought to light a security hole that can be difficult to secure at scale. Currently Opvizor is the only one that I know of that makes this type of appliance, but that doesn't stop the many possible clones of thi...