Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ensure installers can limit ingress access from public internet #100

Open
2 of 3 tasks
phillipedwards opened this issue Jun 5, 2023 · 3 comments
Open
2 of 3 tasks
Assignees
Labels
kind/enhancement Improvements or new features

Comments

@phillipedwards
Copy link
Contributor

phillipedwards commented Jun 5, 2023

Hello!

  • Vote on this issue by adding a 👍 reaction
  • If you want to implement this feature, comment to let us know (we'll work with you on design, scheduling, etc.)

Issue details

By default, public network access is assumed by all installers. This means the self-hosted service is open to all users much like app.pulumi.com, which is not ideal for customers. They'd likely want to restrict network access based on something like an IP range.

The ECS installer allows a config value, seen here where the user can provide a whitelist.

We should implement a similar configurable solution for all other solutions.

Because I like todo lists:

Affected area/feature

@phillipedwards phillipedwards added kind/enhancement Improvements or new features needs-triage Needs attention from the triage team labels Jun 5, 2023
@pierskarsenbarg pierskarsenbarg self-assigned this Jun 6, 2023
@phillipedwards phillipedwards removed the needs-triage Needs attention from the triage team label Jun 6, 2023
@pierskarsenbarg
Copy link
Member

@pierskarsenbarg
Copy link
Member

@phillipedwards Are you aversed to using cloud-specific ingress methods: by that I mean we've got load balancer ingress for EKS, and there's an API Gateway ingress for AKS (although there was a limitation in CORS which is why it's not being used right now) and presumably something similar for GKE

@phillipedwards
Copy link
Contributor Author

@pierskarsenbarg I'm not however, we should be able to limit ingress with nginx ingress for all k8s fairly easily.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement Improvements or new features
Projects
None yet
Development

No branches or pull requests

2 participants