Commit f30634da authored by Matthias's avatar Matthias
Browse files

add IP-based access restrictions

parent 86732927
Pipeline #33001 passed with stages
in 2 minutes and 1 second
......@@ -24,4 +24,6 @@ topicDrupalExport: 'mb-gi-drupal-export-prod'
tfvReportingTopicName: "mb-di-reporting-prod"
tfvTopicName: "mb-di-data-transform-prod"
clearCacheUrl: "/de/memobase/ingestapi/clear_cache"
\ No newline at end of file
clearCacheUrl: "/de/memobase/ingestapi/clear_cache"
whitelistSourceRange: "132.152.230.209"
\ No newline at end of file
......@@ -24,4 +24,6 @@ topicDrupalExport: 'mb-gi-drupal-export-stage'
tfvReportingTopicName: "mb-di-reporting-stage"
tfvTopicName: "mb-di-data-transform-stage"
clearCacheUrl: "/de/memobase/ingestapi/clear_cache"
\ No newline at end of file
clearCacheUrl: "/de/memobase/ingestapi/clear_cache"
whitelistSourceRange: "132.152.230.210"
\ No newline at end of file
......@@ -24,4 +24,6 @@ topicDrupalExport: 'mb-gi-drupal-export-prod'
tfvReportingTopicName: "mb-di-reporting-prod"
tfvTopicName: "mb-di-data-transform-prod"
clearCacheUrl: "/de/memobase/ingestapi/clear_cache"
\ No newline at end of file
clearCacheUrl: "/de/memobase/ingestapi/clear_cache"
whitelistSourceRange: "132.152.0.0/16"
\ No newline at end of file
......@@ -7,6 +7,7 @@ metadata:
cert-manager.io/cluster-issuer: letsencrypt-prod
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/rewrite-target: /
nginx.ingress.kubernetes.io/whitelist-source-range: {{ .Values.whitelistSourceRange }}
spec:
tls:
- hosts:
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment