ministryofjustice / cloud-platform

Documentation on the MoJ cloud platform
MIT License
84 stars 44 forks source link

Use Modsec for all Cloud Platform apps that have ingress #5646

Open poornima-krishnasamy opened 3 months ago

poornima-krishnasamy commented 3 months ago

And CP app that open in the internet which has ingress, Check if those apps need a ingress and should be accessed externally. If yes, configure to be behind the modsecurity.

reports.cloud-platform.service.justice.gov.uk/dashboard modules.apps.live.cloud-platform.service.justice.gov.uk cloud-platform-metrics.apps.live.cloud-platform.service.justice.gov.uk (if possible perhaps we don't need this URL to be external - it's used by prometheus to scrape and could probably be removed and an internal URL used instead)

Communicate changes

Questions / Assumptions

Definition of done

Reference

How to write good user stories

mikebell commented 1 month ago

hoodaw is now running on modsec

mikebell commented 1 month ago

go-get-module done

mikebell commented 1 month ago

Paused the rollout of metrics. Switching to modsec didn't go as planned. Possibly due to the custom deny headers in the ingress definition but needs testing properly after the firebreak.