18F / tock

We use Tock to track and report our time at 18F
https://18f.gsa.gov/2015/05/21/TockingTime/
Other
120 stars 37 forks source link

Finalize egress work #1695

Closed cantsin closed 5 months ago

cantsin commented 9 months ago

As part of Tock's compliance process, the capability for egress filtering is set up for cloud.gov deployments of Tock. We have set up egress spaces for both staging (which should always be on) and production (not on, but available), but more work needs to be done before we finalize egress for the entire stack:

(added by @jduss4 )

juliaklindpaintner commented 9 months ago

Consider turning this into an epic for TLC crew purposes — will follow up!

alexbielen commented 9 months ago

@cantsin and @edwintorres :

Are you still looking for TLC Crew to help on this next increment (Dec 11 - 25)?

edwintorres commented 8 months ago

@alexbielen yes that's correct

jduss4 commented 8 months ago

I put in a little work running through the steps in the existing documentation and adding more to it here: https://github.com/18F/tock/pull/1706

jduss4 commented 8 months ago

Unfortunately I was not able to complete this card before the break. However, during this time we the following:

  1. Built out the documentation
  2. Redeployed the staging versions of egress + tock and confirmed the behavior works for restricting egress
  3. Experimented (unsuccessfully) with removing the public-egress application security group from tock staging and identified a new area for investigation in the setup for New Relic
cantsin commented 5 months ago

I think we can finally close this issue :) If anything comes up with egress in the future, I'll make a separate ticket. Many thanks to everyone involved!!