Skip to content

Commit

Permalink
Merge remote-tracking branch 'origin/NIT-887_global_protect' into lda…
Browse files Browse the repository at this point in the history
…p-datarefresh-NIT859
  • Loading branch information
georgepstaylor committed Oct 16, 2023
2 parents ace8bea + 727f4e5 commit e95d72f
Show file tree
Hide file tree
Showing 2 changed files with 19 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,24 @@ resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress
cidr_ipv4 = "81.134.202.29/32" # MoJ Digital VPN
}

resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress_https_allowlist_gp" {
security_group_id = aws_security_group.delius_frontend_alb_security_group.id
description = "access into delius core frontend alb over https"
from_port = "443"
to_port = "443"
ip_protocol = "tcp"
cidr_ipv4 = "35.176.93.186/32" # Global Protect VPN
}

resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress_http_allowlist_gp" {
security_group_id = aws_security_group.delius_frontend_alb_security_group.id
description = "access into delius core frontend alb over http (will redirect)"
from_port = "80"
to_port = "80"
ip_protocol = "tcp"
cidr_ipv4 = "35.176.93.186/32" # Global Protect VPN
}

resource "aws_vpc_security_group_egress_rule" "delius_core_frontend_alb_egress_to_service" {
security_group_id = aws_security_group.delius_frontend_alb_security_group.id
description = "access delius core frontend service from alb"
Expand Down
1 change: 1 addition & 0 deletions terraform/environments/delius-jitbit/lb.tf
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ resource "aws_security_group" "load_balancer_security_group" {
to_port = 443
cidr_blocks = [
"81.134.202.29/32", # MoJ Digital VPN
"35.176.93.186/32", # Global Protect VPN
"217.33.148.210/32", # Digital studio
"195.59.75.0/24", # ARK internet (DOM1)
"194.33.192.0/25", # ARK internet (DOM1)
Expand Down

0 comments on commit e95d72f

Please sign in to comment.