mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 02:26:19 +00:00
misc: some more updates in examples
This commit is contained in:
@@ -337,18 +337,18 @@ spec:
|
|||||||
port: 6379
|
port: 6379
|
||||||
```
|
```
|
||||||
|
|
||||||
**Infrastructure firewall considerations**. In addition to the universal host firewalls, implement cloud-level security:
|
**Infrastructure firewall considerations**. In addition to the universal host firewalls, implement infrastructure-level security:
|
||||||
|
|
||||||
```bash
|
For cloud deployments (AWS Security Groups, Azure NSGs, or GCP Firewall Rules):
|
||||||
# Example: AWS Security Groups, Azure NSGs, or GCP Firewall Rules
|
|
||||||
# Allow ingress from load balancer to NodePort/ClusterIP service
|
|
||||||
# Allow egress to managed databases
|
|
||||||
# Block all other traffic
|
|
||||||
|
|
||||||
# For on-premises, ensure node-level firewalls allow:
|
- Allow ingress from load balancer to NodePort/ClusterIP service
|
||||||
# - Ingress traffic from ingress controllers
|
- Allow egress to managed databases
|
||||||
# - Egress traffic to external services (databases, SMTP)
|
- Block all other traffic
|
||||||
```
|
|
||||||
|
For on-premises deployments, ensure node-level firewalls allow:
|
||||||
|
|
||||||
|
- Ingress traffic from ingress controllers
|
||||||
|
- Egress traffic to external services (databases, SMTP)
|
||||||
|
|
||||||
#### Access Control
|
#### Access Control
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user