Hacker News new | past | comments | ask | show | jobs | submit login

From Algolia's outage retrospective:

  What we did so far:
  We’ve secured the impacted SaltStack service by updating it and adding additional IP filtering, allowing only our servers to connect to it.

So clearly unrestricted access wasn't a necessity.

I understand it's a pain, I've been running a 1000+ server stack with puppet on a public network and relied on iptables to secure it. But I'd rather cope with the daily iptable rules update than having to fight a 0-day exploit...




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: