Open ports cannot be restricted to an IP or domain
Bug #1321407 reported by
Nate Finch
This bug affects 5 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Canonical Juju |
Fix Released
|
Wishlist
|
Unassigned |
Bug Description
Right now, if you open a port on a node to the outside network, it's open to the entire network - there's no way to just expose it to a limited audience.
Reported here: http://
tags: | added: security |
tags: | added: production |
Changed in juju-core: | |
status: | New → Triaged |
importance: | Undecided → Medium |
Changed in juju: | |
milestone: | none → 2.8-beta1 |
Changed in juju: | |
milestone: | 2.8-beta1 → 2.9-beta1 |
Changed in juju: | |
milestone: | 2.9-beta1 → 2.9-rc1 |
Changed in juju: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
This is pretty inconvenient when combined with the lack of intra-environment isolation. If you have some slightly untrustworthy services, the free-for-all security groups within an environment mean you need to have them in a separate one. But that requires that you expose some services from the trusted environment, and this bug means you then need to firewall them manually.
Something like "juju expose --to NETWORK/MASK" might work, though in my specific case I need a private API port to be restricted while a webapp port on the same service should be public.