-
Notifications
You must be signed in to change notification settings - Fork 25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
MP+ firewall rules #490
Comments
The firewall rules change has been planned for 19th July. |
Seems to be OK, GitHub and GitLab appears to be working, also reporting back is fine. Unless there is an issue with some of the self-hosted GitLab instances or dist-git, I'd expect issues to appear during the sync-release jobs. |
Missed:
|
Sentry issue: PCKT-002-PACKIT-SERVICE-64C |
Latest update:
|
Pinged on the ticket, moving to blocked till we get a response |
Scraped from the specfiles:
@mfocko to create a ticket |
🎉 |
When deploying to the MP+, based on the ESS requirement for monitoring the network traffic, all of the egress (outgoing network connections) are implicitly denied and must be requested to be allowed.
Links to relevant parts of the “documentation”:
TODO:
Preliminary list of the required domains (it may be required to translate to IP subnets :/):
src.fedoraproject.org
is reachable viacurl
, but not viassh
(similarly forgithub.com
) (could've been a user error on my end though)The text was updated successfully, but these errors were encountered: