Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add all public endpoints to list of domains to allow in firewalls #482

Merged
merged 5 commits into from
Feb 24, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,37 @@ $ python3

### DNS allowlist

In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:
In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services provided by Seqera, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:

- `cloud.seqera.io`
- `api.cloud.seqera.io`
- `user-data.cloud.seqera.io`
- `tower.nf`
- `api.tower.nf`
- `connect.cloud.seqera.io` and its subdomains `*.connect.cloud.seqera.io`
- `hub.seqera.io`
- `intern.seqera.io`
- `wave.seqera.io`
- `community.wave.seqera.io`
- `cerbero.seqera.io`
- `public.cr.seqera.io`
- `auth.cr.seqera.io`
- `cr.seqera.io`
- `licenses.seqera.io`
- `api.multiqc.info`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `community-cr-prod.seqera.io`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `public-cr-prod.seqera.io`
- `wave-cache-prod-cloudflare.seqera.io`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `community-cr-prod.seqera.io.cdn.cloudflare.net`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `public-cr-prod.seqera.io.cdn.cloudflare.net`
- `wave-cache-prod-cloudflare.seqera.io.cdn.cloudflare.net`

If you chose to filter by specific DNS records, please note that new services may be added in the future.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,37 @@ $ python3

### DNS allowlist

In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:
In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services provided by Seqera, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:

- `cloud.seqera.io`
- `api.cloud.seqera.io`
- `user-data.cloud.seqera.io`
- `tower.nf`
- `api.tower.nf`
- `connect.cloud.seqera.io` and its subdomains `*.connect.cloud.seqera.io`
- `hub.seqera.io`
- `intern.seqera.io`
- `wave.seqera.io`
- `community.wave.seqera.io`
- `cerbero.seqera.io`
- `public.cr.seqera.io`
- `auth.cr.seqera.io`
- `cr.seqera.io`
- `licenses.seqera.io`
- `api.multiqc.info`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `community-cr-prod.seqera.io`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `public-cr-prod.seqera.io`
- `wave-cache-prod-cloudflare.seqera.io`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `community-cr-prod.seqera.io.cdn.cloudflare.net`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `public-cr-prod.seqera.io.cdn.cloudflare.net`
- `wave-cache-prod-cloudflare.seqera.io.cdn.cloudflare.net`

If you chose to filter by specific DNS records, please note that new services may be added in the future.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,37 @@ $ python3

### DNS allowlist

In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:
In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services provided by Seqera, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:

- `cloud.seqera.io`
- `api.cloud.seqera.io`
- `user-data.cloud.seqera.io`
- `tower.nf`
- `api.tower.nf`
- `connect.cloud.seqera.io` and its subdomains `*.connect.cloud.seqera.io`
- `hub.seqera.io`
- `intern.seqera.io`
- `wave.seqera.io`
- `community.wave.seqera.io`
- `cerbero.seqera.io`
- `public.cr.seqera.io`
- `auth.cr.seqera.io`
- `cr.seqera.io`
- `licenses.seqera.io`
- `api.multiqc.info`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `community-cr-prod.seqera.io`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `public-cr-prod.seqera.io`
- `wave-cache-prod-cloudflare.seqera.io`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `community-cr-prod.seqera.io.cdn.cloudflare.net`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `public-cr-prod.seqera.io.cdn.cloudflare.net`
- `wave-cache-prod-cloudflare.seqera.io.cdn.cloudflare.net`

If you chose to filter by specific DNS records, please note that new services may be added in the future.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,37 @@

### DNS allowlist

In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:
In order for you to access resources such as Fusion tarballs, `nf-xpack` files, Wave cloud containers and other services provided by Seqera, you'll need to add `*.seqera.io.cdn.cloudflare.net` to the allowlist in your network firewall. If DNS wildcards aren't supported by your firewall, you can use the following:

Check failure on line 33 in platform_versioned_docs/version-24.2/enterprise/advanced-topics/firewall-configuration.mdx

View workflow job for this annotation

GitHub Actions / runner / vale

[vale] reported by reviewdog 🐶 [Vale.Spelling] Did you really mean 'allowlist'? Raw Output: {"message": "[Vale.Spelling] Did you really mean 'allowlist'?", "location": {"path": "platform_versioned_docs/version-24.2/enterprise/advanced-topics/firewall-configuration.mdx", "range": {"start": {"line": 33, "column": 201}}}, "severity": "ERROR"}

- `cloud.seqera.io`
- `api.cloud.seqera.io`
- `user-data.cloud.seqera.io`
- `tower.nf`
- `api.tower.nf`
- `connect.cloud.seqera.io` and its subdomains `*.connect.cloud.seqera.io`
- `hub.seqera.io`
- `intern.seqera.io`
- `wave.seqera.io`
- `community.wave.seqera.io`
- `cerbero.seqera.io`
- `public.cr.seqera.io`
- `auth.cr.seqera.io`
- `cr.seqera.io`
- `licenses.seqera.io`
- `api.multiqc.info`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `community-cr-prod.seqera.io`
- `fusionfs.seqera.io`
- `nf-xpack.seqera.io`
- `public-cr-prod.seqera.io`
- `wave-cache-prod-cloudflare.seqera.io`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `community-cr-prod.seqera.io.cdn.cloudflare.net`
- `fusionfs.seqera.io.cdn.cloudflare.net`
- `nf-xpack.seqera.io.cdn.cloudflare.net`
- `public-cr-prod.seqera.io.cdn.cloudflare.net`
- `wave-cache-prod-cloudflare.seqera.io.cdn.cloudflare.net`

If you chose to filter by specific DNS records, please note that new services may be added in the future.
Expand Down