Exposing Kong Admin API to internal network









up vote
1
down vote

favorite












We have a Kong Gateway running within a VPC in AWS. Currently, the Admin API for the Kong Gateway is restricted to only localhost traffic using



export KONG_ADMIN_LISTEN="127.0.0.1:8001"
export KONG_ADMIN_LISTEN_SSL="127.0.0.1:8444"


We'd like to allow microservices within the same VPC to register their own routes when they get deployed. In order to do this we need to open up the KONG_ADMIN_LISTEN to other machines within the VPC. However, we don't want any machine outside the network to be able to access it.



I'm pretty new to networking and did not find the Kong docs very clear on how to do this. Any recommendations?










share|improve this question

























    up vote
    1
    down vote

    favorite












    We have a Kong Gateway running within a VPC in AWS. Currently, the Admin API for the Kong Gateway is restricted to only localhost traffic using



    export KONG_ADMIN_LISTEN="127.0.0.1:8001"
    export KONG_ADMIN_LISTEN_SSL="127.0.0.1:8444"


    We'd like to allow microservices within the same VPC to register their own routes when they get deployed. In order to do this we need to open up the KONG_ADMIN_LISTEN to other machines within the VPC. However, we don't want any machine outside the network to be able to access it.



    I'm pretty new to networking and did not find the Kong docs very clear on how to do this. Any recommendations?










    share|improve this question























      up vote
      1
      down vote

      favorite









      up vote
      1
      down vote

      favorite











      We have a Kong Gateway running within a VPC in AWS. Currently, the Admin API for the Kong Gateway is restricted to only localhost traffic using



      export KONG_ADMIN_LISTEN="127.0.0.1:8001"
      export KONG_ADMIN_LISTEN_SSL="127.0.0.1:8444"


      We'd like to allow microservices within the same VPC to register their own routes when they get deployed. In order to do this we need to open up the KONG_ADMIN_LISTEN to other machines within the VPC. However, we don't want any machine outside the network to be able to access it.



      I'm pretty new to networking and did not find the Kong docs very clear on how to do this. Any recommendations?










      share|improve this question













      We have a Kong Gateway running within a VPC in AWS. Currently, the Admin API for the Kong Gateway is restricted to only localhost traffic using



      export KONG_ADMIN_LISTEN="127.0.0.1:8001"
      export KONG_ADMIN_LISTEN_SSL="127.0.0.1:8444"


      We'd like to allow microservices within the same VPC to register their own routes when they get deployed. In order to do this we need to open up the KONG_ADMIN_LISTEN to other machines within the VPC. However, we don't want any machine outside the network to be able to access it.



      I'm pretty new to networking and did not find the Kong docs very clear on how to do this. Any recommendations?







      networking microservices amazon-vpc kong






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 10 at 1:20









      Brian

      1,20732453




      1,20732453






















          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          Can you say a little more about what sort of configuration of Kong you are hoping your microservices will be able to perform?






          share|improve this answer




















            Your Answer






            StackExchange.ifUsing("editor", function ()
            StackExchange.using("externalEditor", function ()
            StackExchange.using("snippets", function ()
            StackExchange.snippets.init();
            );
            );
            , "code-snippets");

            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "1"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53235216%2fexposing-kong-admin-api-to-internal-network%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes








            up vote
            0
            down vote













            Can you say a little more about what sort of configuration of Kong you are hoping your microservices will be able to perform?






            share|improve this answer
























              up vote
              0
              down vote













              Can you say a little more about what sort of configuration of Kong you are hoping your microservices will be able to perform?






              share|improve this answer






















                up vote
                0
                down vote










                up vote
                0
                down vote









                Can you say a little more about what sort of configuration of Kong you are hoping your microservices will be able to perform?






                share|improve this answer












                Can you say a little more about what sort of configuration of Kong you are hoping your microservices will be able to perform?







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Nov 15 at 23:55









                Cooper

                46149




                46149



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Stack Overflow!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.





                    Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


                    Please pay close attention to the following guidance:


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53235216%2fexposing-kong-admin-api-to-internal-network%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Use pre created SQLite database for Android project in kotlin

                    Darth Vader #20

                    Ondo