-
Notifications
You must be signed in to change notification settings - Fork 606
Closed
Labels
researchDetermine technical constraintsDetermine technical constraintsuxUser experienceUser experience
Milestone
Description
Restrict access to APIs by whitelisting ip addresses/cidr. Based on this documentation it might be possible to do it at the service level.
- Investigate
.spec.loadBalancerSourceRangesalthough this ticket isn't related, it has information about how istio can be setup with loadBalancerSourceRanges - Expose ip address ranges list to the user in cluster config for both operator and api loadbalancer
Verify that this approach works for both internet facing and internal loadbalancers.
Additional Information:
Here is a gist with instructions that seemed to have worked for an internet-facing operator loadbalancer.
Metadata
Metadata
Assignees
Labels
researchDetermine technical constraintsDetermine technical constraintsuxUser experienceUser experience