-
Notifications
You must be signed in to change notification settings - Fork 42
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Only apply external IP allowlist to Nexus (#5900)
- Fixes #5892 - Modifies the application of the external services IP allowlist so that it's only relevant for Nexus API servers, rather than all external-facing services (DNS being the other example today). It is not always possible to know the peer addresses for DNS servers in the case of recursive DNS, and so the allowlist cannot directly apply to external DNS. This works by inserting the allowlist entries as a host-filter, which we were doing before, but only on the named VPC Firewall rule for the Nexus VPC Subnet.
- Loading branch information
1 parent
42fe148
commit 7a8ce1f
Showing
3 changed files
with
37 additions
and
11 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters