DigitalOcean home
  • Droplets
  • Spaces
  • Kubernetes
  • Tools & Integrations
  • One-click Apps
  • API Documentation
  • Community
  • Tutorials
  • Q&A
  • Projects
  • Meetups
  • Customers
  • Pricing
  • Docs
  • Support
  • DigitalOcean home
  • Products
    • Droplets

      Scalable compute services.

    • Spaces

      Simple object storage.

    • Kubernetes

      Run managed Kubernetes clusters.

    • Tools & Integrations

      Automate your infrastructure.

    • One-click Apps

      Deploy pre-built applications.

    • API Documentation
  • Customers
  • Community
    • Community Overview

      Connect, share and learn

    • Tutorials

      DevOps and development guides

    • Questions & Answers

      Development and systems Q&A

    • Projects

      Community-built integrations

    Get Involved
    Write for DOnations
    Join us at a Meetup
    Featured Post
    An Introduction to Kubernetes

    by Justin Ellingwood

  • Pricing
  • Docs
  • Support
    • Documentation

    • Contact Support

    • Network Status

  • Home /
  • K8SX-I-30 /
  • New idea
2 Vote

Support loadBalancerSourceRanges in the Kubernetes and Load Balancer integration

Currently, using the DigitalOcean Load Balancer product from the DO Kubernetes integration exposes all services to the internet.

In the K8s documentation you can specify loadBalancerSourceRanges in external load balancers to block traffic to your services from anywhere outside of your cluster, like so:

 loadBalancerSourceRanges:  - 10.0.0.0/8

This is supported on Google Compute Engine, Google Kubernetes Engine, AWS Elastic Kubernetes Service, Azure Kubernetes Service, and IBM Cloud Kubernetes Service.

This has been posted in this community question which has 12 replies, indicating that I'm not the only one who needs this for DigitalOcean's Load Balancer product to be viable with Kubernetes. Without this, if someone finds out your node IP, they can connect to your services directly which is an attack vector.

[Jun 30 2020 update: I've given up on DigitalOcean: I'm switching to Azure.]

  • Guest
  • Jun 12 2020
  • Needs review
Kubernetes
  • Comments (1)
  • Votes (2)
  • Attach files
  • Guest commented
    30 Jun, 2020 09:13am

    FWIW I'm switching to Azure from DigitalOcean.

    ×

    Attachments Open full size

Log in / Sign up

Identify yourself with your email address

Subscribe

You won't be notified about changes to this idea.

Related ideas

DigitalOcean home

© 2018 DigitalOcean, LLC. All rights reserved.
Proudly made in NY

  • Twitter
  • Facebook
  • Instagram
  • YouTube
  • LinkedIn
  • Glassdoor
Company
About
Leadership
Blog
Careers
Partner Network
Referral Program
Events
Press
Legal & Security
Products
Droplets
Spaces
Kubernetes
Tools & Integrations
One-click Apps
API
Pricing
Documentation
Release Notes
Community
Tutorials
Meetups
Q&A
Write for DOnations
Droplets for Demos
Hatch
Shop Swag
Research Program
Currents Research
Open Source
Support
Contact Support
FAQ
Network Status