Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: filter DNS queries from the datasets VPC using the Route53 Fire…
…wall We don't know of any particular thing in the datasets VPC that allows users to make DNS queries, especially to unauthorised servers, so this is a defense in depth/just in case change. We are soon to put ArrangoDB in the dame VPC, so I think it makes sense to tighten things down as we increase the surface area otherwise. It is set to only allow queries to amazonaws.com domains, and block everything else. While we might be able to block it further in future, this is a step forward in terms of locking things down. In the notebooks VPC we have a similar setup, but with what is essentially our own custom firewall, written before the Route53 Firewall existed. If this goes well, potentially we could shut that down in favour of this for the notebooks VPC.
- Loading branch information