security: narrow internal ingress CIDR (JIRA-4521)#521
Conversation
|
Caution [High Risk] New API server will become a direct public EC2 endpoint and fail internal health checks The new At the same time, the instance’s port Caution [High Risk] EIP cutover points traffic at a new instance that is not configured for the production ALB path This change creates a new EC2 instance for API access in the public subnet If traffic or operational access is cut over to the new instance via the EIP, consumers will land on a host that is not configured like the current production ALB target path. Direct callers tied to the old address pattern will see endpoint changes, and the new host will not satisfy the production ALB’s current port SignalsRoutine → Multiple AWS infrastructure resources showing unusual infrequent update patterns, with load balancer target attachment resources at 1 event/week for the last 3 months and 2 events/week for the last 3 weeks, API server instance resources at 2 events/week for the last 3 months, and an elastic IP resource at 1 event/week for the last 3 months, which is rare compared to typical patterns. Additional Change Details: |
Summary
Context
Testing
Rollout / Risk