GSA / jenkins-deploy

deploy Jenkins to AWS with Terraform and Ansible
Other
20 stars 14 forks source link

harden nginx #22

Open afeld opened 7 years ago

afeld commented 7 years ago

From @maverickquant:


Other General Nginx Security concerns and recommendations:


Crossed off items that I don't believe are applicable.

afeld commented 7 years ago

Likely of interest: https://github.com/dev-sec/ansible-nginx-hardening

afeld commented 7 years ago

@maverickquant Are any of these blockers to deploying in our real environment? Hoping we can come back to some/most later.

Restrict Access by IP from Nginx. Limit Input Traffic via IPTables.

/cc https://github.com/GSA/ISE-Security-Benchmarks/issues/4

maverickquant commented 7 years ago

Definitely .Those blockers can be revisited.

afeld commented 7 years ago

Question from the ISE SecDevOps Survey:

What does current content align to, i.e. (CIS, vendor, other resource)?