# What would openziti arch for this look like

**URL:** <https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616>\
**Category:** Ziti Overlay\
**Created:** [May 30, 2024, 4:00am UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616 "2024-05-30T04:00:45Z")\
**Posts on this page:** 10\
**Page:** 5

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [June 10, 2024, 11:53am UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/83 "2024-06-10T11:53:00Z")

</div>

> [@sadath-12](#):
>
> please do confirm if I understood router and controller properly

Yes, you seem to have a good grasp.

> [@sadath-12](#):
>
> would be great if I can get a bit clarity on difference btw ctrl and mgmt

there is no longer a `mgmt` section. Where did you find that reference, I'd like to make sure the doc is accurate. `ctrl` is the port how routers connect to the controller.

> [@sadath-12](#):
>
> Also was curious to understand how the controller registers private network routers and communicate with it , sharing links or explanation anything is fine with this regards

The routers reach out to the public controller and establish a control channel, then the router and controller are able to communicate.

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 10, 2024, 12:04pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/84 "2024-06-10T12:04:47Z")

</div>

here [It's All Software | OpenZiti](https://openziti.io/docs/learn/introduction/openziti-is-software#fabric) and also [GitHub - netfoundry/ziti\_router\_auto\_enroll](https://github.com/netfoundry/ziti_router_auto_enroll/tree/main) asking about mgmt and fabric ports

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 12, 2024, 4:46pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/85 "2024-06-12T16:46:14Z")

</div>

@qrkourier just confirming before hand . I am deploying routers only at private networks and I would follow with this command

```auto
helm upgrade --install "private-router123" openziti/ziti-router \
--namespace ziti \
--set-file enrollmentJwt=./router1.jwt \
--set edge.advertisedHost=private-router123-edge.ziti.svc.cluster.local \
--set linkListeners.transport.service.enabled=false \
--set ctrl.endpoint="{{ ctrlPlane.advertisedHost }}:6262"

```

So one question which I should have asked before is , can I just always deploy private routers on every private network I have and it will just work fine?

From my perps , it seems like if we deploy private routers it only listens to controller and in that way if we deploy all private routers we are going to overload controller maybe ?

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 12, 2024, 10:42pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/86 "2024-06-12T22:42:37Z")

</div>

Private routers will help service performance by providing a local data path. Ensure the router has an edge listener the local identities are allowed to use. The data will stay local if the destination is local as long as the private router is available. If the private router is unavailable, the data can still flow through a public router, but it takes longer to relay. Only routers carry service payload data, so private routers do not burden the controller more than public routers.

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 13, 2024, 2:57pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/87 "2024-06-13T14:57:36Z")

</div>

ohk one more thing --\> while installing public routers of loadbalancer type , Initially how do we know the advertising and link listener URL of routers , because loadbalancer gets created later and we had to upgrade the router to add that loadbalancer url to make it work .

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 14, 2024, 12:28pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/88 "2024-06-14T12:28:26Z")

</div>

I assume a public router is reachable on a public IP (by FQDN), and a private router is not. Both public and private can be configured to advertise edge and link listeners, and it's advisable to advertise link listeners only on a public IP (as a FQDN). It is a best practice for private routers to have an edge listener and no link listener, and for public routers to have both configured. This reduces log noise from unreachable advertisements, which can obscure the problem during troubleshooting.

You're asking how one knows a router's advertised address (e.g., `router1.edge.ziti.example.com:443`) before the LoadBalancer is provisioned.

Here's the order of things that I expect.

1. Choose a FQDN like `router1.edge.ziti.example.com` for the advertised addresses of the public router.
2. Deploy the router, using this FQDN, with Helm inputs that specify its edge service is of type LoadBalancer.
3. Learn the EXTERNAL\_IP that becomes provisioned by the cloud provider's service controller for the LoadBalancer service.
4. Create a DNS record with the service's external (public) IP.

Now clients can resolve the FQDN to the LoadBalancer service and reach the router's edge listener.

Reminder: the LoadBalancer provisioned by the cloud's service controller _must_ be a TCP proxy (TLS passthrough). If it terminates TLS (has a server certificate), then the router will not function.

You can use these same steps with any TLS server provided by a controller or router that needs to be reachable by a FQDN (a public, advertised address).

It's not required to use a LoadBalancer service, however. That's one way to publish a cluster service. The other options are ClusterIP+Ingress/Gateway and NodePort.

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 17, 2024, 6:05am UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/89 "2024-06-17T06:05:34Z")

</div>

> [@qrkourier](#):
>
> ```auto
> helm upgrade --install "private-router123" openziti/ziti-router \
> --namespace ziti \
> --set-file enrollmentJwt=./router1.jwt \
> --set edge.advertisedHost=private-router123-edge.ziti.svc.cluster.local \
> --set linkListeners.transport.service.enabled=false \
> --set ctrl.endpoint="{{ ctrlPlane.advertisedHost }}:6262"
> 
> ```

Hi @qrkourier , I get these errors now when I deploy routers with that command

```auto
{"error":"error dialing outgoing link [l/1pn4xkobBN7j1nE4Tc103n@10]: error dialing payload channel for [l/1pn4xkobBN7j1nE4Tc103n]: dial tcp 10.0.157.16:3031: i/o timeout","file":"github.com/openziti/ziti/router/link/link_registry.go:478","func":"github.com/openziti/ziti/router/link.(*linkRegistryImpl).evaluateLinkState.func1","iteration":10,"key":"default-\u003etls:NxWYfPm0eH-\u003edefault","level":"error","linkId":"1pn4xkobBN7j1nE4Tc103n","msg":"error dialing link","time":"2024-06-17T06:02:00.469Z"}
{"file":"github.com/openziti/ziti/router/link/link_state.go:97","func":"github.com/openziti/ziti/router/link.(*linkState).updateStatus","iteration":10,"key":"default-\u003etls:NxWYfPm0eH-\u003edefault","level":"info","linkId":"1pn4xkobBN7j1nE4Tc103n","msg":"status updated","newState":"dialFailed","oldState":"dialing","time":"2024-06-17T06:02:00.469Z"}

```

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 17, 2024, 6:13am UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/90 "2024-06-17T06:13:41Z")

</div>

ohk again the same terminator issue

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 17, 2024, 1:51pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/91 "2024-06-17T13:51:22Z")

</div>

I'll offer some guidelines to help me help you because I'm unable to discern the nature of the problem based on what you posted. Reminder: router link errors might not be a significant problem, but may be "noise" due to unreachable link listeners. We've talked about this a few times in this topic. Does it make sense?

1. Start a new topic for a new problem. This ensures the solution will be helpful to other forum users and defines the context and the problem. This also welcomes anyone that understands the problem to comment.
2. Paste text snippets that describe the symptom (the visible signs of dysfunction), not screenshots, if possible. Thank you for this, it saves a lot of time for the responder and makes the symptom searchable for other users.
3. Provide a step-by-step procedure that recreates the same problem every time (reproduction of the issue). This helps you to think through the issue and sometimes find the solution before posting. Please share the solution anyway for other users!

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 17, 2024, 4:50pm UTC](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616/92 "2024-06-17T16:50:00Z")

</div>

sure thanks @qrkourier , will make it organised and if I find any issues ill point them to this thread too

[Previous page](https://openziti.discourse.group/t/what-would-openziti-arch-for-this-look-like/2616.md?page=4)
