cloudfoundry / loggregator-agent-release

Apache License 2.0
14 stars 26 forks source link

Get rid of the `blacklisted_syslog_ranges` feature #176

Open Benjamintf1 opened 1 year ago

Benjamintf1 commented 1 year ago

I don't think anyone actually uses it, and even if they tried, I think it would be hard to make that feature actually useful. We should remove this functionality and the code associated with it.

mkocher commented 1 year ago

This feature dates back to publicly accessible CF instances to prevent users from ddos'ing random IPs. I'm not sure if we want to say that's not a valid use case for CF?

Benjamintf1 commented 1 year ago

CF users always have had and continue to be able to ddos random ips if they wanted to.

The explaination I heard was to prevent exfiltration of logs/metrics to undesired ip addresses(which seems to me like being able to remove addresses rather then ip ranges would be easier to do in many cases?, or perhaps removing all external ip addresses or so on would be a much more functional usecase)

The biggest thing is I think that nobody is utilizing this feature at all.