I left out some details;
We are running with user auth. But, only user auth is not sufficient. We need to have IP restrictions as well.
Doing that with a firewall (eg. iptables) means working with another group. While *technically* feasible, it presents a number of non-technical hurdles I'd rather avoid. (The pain of working in a large company.)
I am running cherrpy "directly". (I.e. not using Apache). I guess I could move it over to using Apache. But, that's another thing that needs to be maintained. I like Apache... I just want to minimize the number of moving parts.
We are moving from using the peer publishing system to the netapi. The peer publishing has a config that limits what clients can do what. The "external_auth" config limits which minions the jobs published can act on. (Yes, I understand that the netapi and peer publishing systems are totally different.) So, while it seems odd for salt to manage what hosts have access, in our case, it makes sense because we are migrating from the peer publishing system.
So, I should have asked; how do you limit by IP in cherrypy, not salt itself.
Thanks!
Craig
________________________________________
From: salt-...@googlegroups.com [salt-...@googlegroups.com] on behalf of Jakub Mikusek [ja...@mikusek.org]
Sent: Friday, July 19, 2013 1:10 AM
To: salt-...@googlegroups.com
Subject: Re: [salt-users] salt-api: limit access by IP
Hi Craig,
Hope that helped!
Regards,
Jakub
--
You received this message because you are subscribed to the Google Groups "Salt-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to salt-users+...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.