mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-10-02 17:53:14 +00:00
Add ALB egress rule for Forgejo target group
ALB security group has restricted outbound — needed explicit egress to the Forgejo SG on port 3000 for health checks.
This commit is contained in:
parent
9e0a14e5b8
commit
ed41fd4eac
1 changed files with 3 additions and 1 deletions
|
|
@ -33,8 +33,10 @@ export class ForgejoStack extends cdk.Stack {
|
||||||
});
|
});
|
||||||
|
|
||||||
const albSg = ec2.SecurityGroup.fromSecurityGroupId(
|
const albSg = ec2.SecurityGroup.fromSecurityGroupId(
|
||||||
this, "AlbSg", "sg-0b0301deed193258a"
|
this, "AlbSg", "sg-0b0301deed193258a",
|
||||||
|
{ allowAllOutbound: false }
|
||||||
);
|
);
|
||||||
|
albSg.addEgressRule(sg, ec2.Port.tcp(3000), "Forgejo HTTP");
|
||||||
sg.addIngressRule(albSg, ec2.Port.tcp(3000), "HTTP from ALB");
|
sg.addIngressRule(albSg, ec2.Port.tcp(3000), "HTTP from ALB");
|
||||||
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC");
|
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC");
|
||||||
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN");
|
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN");
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue