Skip to content

Commit 83c4ddf

Browse files
committed
Update Firewall and DDoS protection info
1 parent 97bce5d commit 83c4ddf

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

modules/sdpolicy-security.adoc

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,8 @@ $ oc adm policy add-cluster-role-to-group self-provisioner system:authenticated:
7777

7878
[id="network-security_{context}"]
7979
== Network security
80-
With {product-title} on AWS, AWS provides a standard DDoS protection on all Load Balancers, called AWS Shield. This provides 95% protection against most commonly used level 3 and 4 attacks on all the public facing Load Balancers used for {product-title}. A 10-second timeout is added for HTTP requests coming to the haproxy router to receive a response or the connection is closed to provide additional protection.
80+
Each {product-title} cluster is protected by a secure network configuration at the cloud infrastructure level using firewall rules (AWS Security Groups or Google Cloud Compute Engine firewall rules). {product-title} customers on AWS are also protected against DDoS attacks with link:https://docs.aws.amazon.com/waf/latest/developerguide/ddos-overview.html[AWS Shield Standard].
81+
Similarly, all GCP load balancers and public IP addresses used by {product-title} on GCP are protected against DDoS attacks with link:https://cloud.google.com/armor/docs/managed-protection-overview[Google Cloud Armor Standard].
8182

8283
[id="etcd-encryption_{context}"]
8384
== etcd encryption

0 commit comments

Comments
 (0)