You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
====================
10. Server Configuration
--------------------
Instance Name : <null>
Base URI : http://0.0.0.0:5000
Canonical URI : <null>
Listen URIs : http://0.0.0.0:5000, http://0.0.0.0:5341
Ingestion Ports : 5341
Using SQL Metastore : No
Using PostgreSQL Metastore : No
Indexer Priority : 0.0
Query Parallelism : 4
Disk Reader Limit : 5
Enabled Features :
Expected result: port 5000 should not accept any ingestions (provide UI only).
Actual result: serilog successfully posts events to SEQ via 5000 port.
The text was updated successfully, but these errors were encountered:
This is by design; the ingestion port restriction sets the specified port to ingestion only, e.g. so that it can be exposed to a less-secure environment without also exposing Seq's UI and API.
There's currently no support for preventing ingestion on a port that otherwise exposes the UI/API; let me know if you have a scenario where this would be desirable.
@nblumhardt thank you for the explanation. I thought to use it in a opposite manner - make unprotected ingress port available in the protected network, so all the apps can post events without any authorization overhead, and make UI+login available to the public. So public endpoint shouldn't accept any events.
@alishchytovych to implement that scheme, you can simply remove the Ingest permission from the ones allowed to your limited UI users (Settings > Users > Edit). Let me know if this helps.
Using SEQ (seq:latest) in Kubernetes, with the container settings:
allows events ingestion on 5000 port.
In the diagnostic report I see the following:
Expected result: port 5000 should not accept any ingestions (provide UI only).
Actual result: serilog successfully posts events to SEQ via 5000 port.
The text was updated successfully, but these errors were encountered: