Skip to content

Prevent Hyperion from being invoked from outside the beamline #731

@rtuck99

Description

@rtuck99

Once Hyperion is deployed to production beamline we will need some way of ensuring that plans can't be executed by calls from outside the beamline network.

As a minimum we should ensure that only HEAD/GET requests are permitted, it seems like this ought to be something that we can do in the kubernetes Ingress configuration.

If this isn't possible, we could just block all access from outside the beamline.

Acceptance Criteria

  • Clients from outside the beamline network cannot execute Hyperion plans or make other writes

Metadata

Metadata

Assignees

Labels

hyperionIssues for Hyperion, the Bluesky UDC stack

Type

No type

Projects

Status

Blocked

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions