https://flyte.org logo
a

Attila Nagy

05/23/2022, 10:00 PM
Hi, When deploying with https://docs.flyte.org/en/latest/deployment/aws/opta.html#deployment-aws-opta, what's the canonical way for setting up an allowlist (list of permitted IPs/networks) for the internet-facing service, so the service isn't open for anyone on the internet?
k

Ketan (kumare3)

05/23/2022, 10:54 PM
cc @JD Palomino can you help here?
j

JD Palomino

05/23/2022, 10:56 PM
more info
a

Attila Nagy

05/24/2022, 9:19 AM
Basically I would like to set up a default deny rule on the load balancer, so only a given set of IP addresses/CIDRs should reach the service.
k

Ketan (kumare3)

05/24/2022, 1:58 PM
@JD Palomino - @Attila Nagy wants to limit access to certain cidrs only. This can be done by modifying the security group for LB, to restrict the ranges
a

Attila Nagy

05/24/2022, 9:08 PM
The opta deployment creates a network load balancer (no security groups, only limited VPC ACLs). Can this be configured in the YAML files?
j

JD Palomino

05/24/2022, 9:12 PM
I can look into this yes
👍 1
2 Views