fix: add fourth IP to pilot ALB allow-list - #206
Merged
Conversation
Contributor
There was a problem hiding this comment.
🟢 Ready to approve
The change is a minimal, consistent update to the existing allow-list in both configs with no apparent behavioral or structural risks beyond the intended access expansion.
This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.
Pull request overview
Adds an additional /32 CIDR to the existing ALB ingress allow-list used to restrict access to the pilot’s backend (app) and frontend load balancers, continuing the security lockdown introduced in #204/#205.
Changes:
- Add
108.48.242.121/32toalb_ingress_cidr_blocksin the frontend app-config. - Add
108.48.242.121/32toalb_ingress_cidr_blocksin the app (backend) app-config.
File summaries
| File | Description |
|---|---|
| infra/frontend/app-config/main.tf | Extends the frontend ALB allow-list by adding a fourth IP CIDR. |
| infra/app/app-config/main.tf | Extends the app ALB allow-list by adding a fourth IP CIDR. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Low
We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket
N/A — follow-up to #204/#205.
Changes
Adds a fourth IP (
108.48.242.121/32) to thealb_ingress_cidr_blocksallow-list for both theappandfrontendapp-configs.Context for reviewers
Small, targeted follow-up — no other changes. Needs 1 approving review per the repo's merge ruleset. After merge, remember prod won't pick this up automatically — needs a manual
workflow_dispatchdeploy for bothDeploy appandDeploy frontendwithenvironment=prod.Testing
terraform fmt -check -diff -recursive infra— clean.Preview environment for frontend
♻️ Environment destroyed ♻️
Preview environment for app
♻️ Environment destroyed ♻️