Skip to content

Investigate ways to whitelist ip addresses for APIs #2003

@vishalbollu

Description

@vishalbollu

Restrict access to APIs by whitelisting ip addresses/cidr. Based on this documentation it might be possible to do it at the service level.

  • Investigate .spec.loadBalancerSourceRanges although this ticket isn't related, it has information about how istio can be setup with loadBalancerSourceRanges
  • Expose ip address ranges list to the user in cluster config for both operator and api loadbalancer

Verify that this approach works for both internet facing and internal loadbalancers.

Additional Information:
Here is a gist with instructions that seemed to have worked for an internet-facing operator loadbalancer.

Metadata

Metadata

Assignees

No one assigned

    Labels

    researchDetermine technical constraintsuxUser experience

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions