Skip to content

Conversation

@DImuthuUpe
Copy link
Contributor

This will restrict following services to selected subnets through ansible.

  • Registry Service
  • Sharing Registry
  • Credential Store
  • Rabbitmq / Admin Portal
  • Zookeeper
  • Database
  • Kafka

Following Service will stay available open to public internet

  • API Service TLS Port
  • Profile Service
  • Keycloak
  • Kafka Rest Proxy
  • Zabbix

Following service were blocked due inactivity and security concerns

  • API Service Insecure Port
  • Orchestrator Service

Copy link
Member

@smarru smarru left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

    1. Changed look good, but did not see any immediate suggestions

@machristie
Copy link
Contributor

This looks good to me. One question, the IU subnets includes II VMs and Jetstream VMs?

@DImuthuUpe DImuthuUpe merged commit 9b3ada7 into master Nov 21, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants