IBM Cloud - Structured Ideas

Welcome to the idea portal for structured ideas (i.e. product feature requests) - A more integrated and automated feedback system to connect your product improvement ideas with IBM product and engineering teams.  Happy submitting!

 

NOTE: All IBM employees must enter Ideas through this Ideas Portal.

Enable "secure" forwarding of client IPs to Container cluster services

CS clusters do not forward client IPs by default as the ALB act as a non-trasparent proxy. So in order to forward the client ip in custom HTTP headers, such as x-forwarded-for , these instructions can be followed.

https://console.bluemix.net/docs/containers/cs_ingress.html#preserve_source_ip

These instructions assume the container applications should insecurely accept the header from any IP as there is no instruction to find and or determine the IP of the ALB. 

Ideally ALBs should be configurable as transparent proxies so no custom deployment or changes are required. However if this is not possible two instructions should be included in the documentation.
1 - how to set up the ALBs to automatically forward the x-forwarded-for header systematically ie through a YAML file
2 - how to get the IP of the ALB routing service as it will be seen by the service container so that i can pass it to the application, thus allowing the application to securely use the custom header from a secure and predetermined source.

Further details are available in support ticket 
https://control.bluemix.net/support/tickets/62895935



  • Guest
  • Sep 19 2018
  • Needs review
  • Attach files

NOTICE TO EU RESIDENTS: per EU Data Protection Policy, if you wish to remove your personal information from the IBM ideas portal, please login to the ideas portal using your previously registered information then change your email to "anonymous@euprivacy.out" and first name to "anonymous" and last name to "anonymous". This will ensure that IBM will not send any emails to you about all idea submissions