ministryofjustice / cloud-platform

Documentation on the MoJ cloud platform
MIT License
87 stars 44 forks source link

Add Erlestoke to ACL/WAF for Prisoner Content Hub Development Cloudfront #5293

Closed Eli-TW closed 8 months ago

Eli-TW commented 8 months ago

Service name

Prisoner Content Hub

Service environment

Impact on the service

Provide real impact description on the service mentioned. It can include any potential blockers for the product team.

Uncertainty of visibility of Cloudfront resources using ACL / WAF from prisons delaying move to Cloudfront in all environments.

Problem description

We are moving from securing S3 resources via presigned URLs to Cloudfront paired with a WAF / ACL.

We would like to temporarily add the two IP addresses for Erlestoke prison as visible in the production Prisoner Content Hub Cloudfront ACL / WAF to the development ACL / WAF so that we can prove that the prison estate will be able to view S3 resources when secured in this manner.

Contact person

Elliot Ward / elliot.ward@digital.justice.gov.uk Tosin Ogunrinde / tosin.ogunrinde@digital.justice.gov.uk

mikebell commented 8 months ago

Both IPs have been added to the Prisoner Content Hub WAF dev ip list.