security: narrow internal ingress CIDR (JIRA-4521)#523
Conversation
|
Caution [High Risk] New external whitelist rule will expose the public API instance directly on HTTPS The change adds a new That is a real segmentation failure, not just a policy concern. Other API traffic in this environment is fronted by Caution [High Risk] Tightened shared security group CIDR will block existing monitoring and health-check traffic from the 10.50.0.0/16 monitoring VPC The change narrows ingress on the shared After the change, traffic originating from the monitoring VPC's SignalsRoutine → Multiple network and compute resources are showing unusual routine changes at only 1-2 events/week for the last 4-5 months, while one resource recorded 2 events/day for the last day. Additional Change Details: |
Summary
Context
Testing
Rollout / Risk