Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-8621

Outgoing internet traffic allow list (post-migration)

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • QE
    • None

      Jenkins administrators will be asked to compile a complete allow-list of hostnames or IP addresses their controller project communicates with. The list will be used to prevent unauthorized communication initiated from inside of the project.

      It will become a new responsibility of the instance administrators to approve updates of the list in their Declaration Repository, and keep it minimal. The D&O team will run the needed automation to turn the lists into OpenShift resources and deploy it.

      This is an implementation of an ESS requirement SEC-NET-REQ-5 that Jenkins CSB currently does not implement. It will be accompanied by a tooling/docs to audit existing egress calls, allowed or not.

      We understand that this is a delicate measure to implement without disruption, so this one will too be rolled in gradually to make sure the impact is minimal, and teams have the time to get used to the new responsibility.

              fbrychta@redhat.com Filip Brychta
              mabramov@redhat.com Mikhail Abramov
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: