1.1.6 • Published 7 years ago
@hs-web-team/serverless-resource-policy v1.1.6
Warning: This package is in development. Please use this package for now.
Serverless Resource Policy
Creates a whitelist for IP or CIDR addresses accessing a serverless application, using serverless resource policies. This enables you to allow requests only from the IP or CIDR addresses you specify.
Private and Public Stages
CIDR and IP addresses are whitelisted by stages.
privateStages: Private to whitelisted CIDR and IP addresses. In the example below, ourdevandstagingstages areprivateStages, so only those CIDR and IP addresses can accessdevandstaging.publicStages: No whitelisting necessary. These stages are public to all CIDR and IP addresses.
How to Use
- Install in your serverless application:
npm install --save @hs-web-team/serverless-resource-policy - In your
serverless.ymlfile, add the@hs-web-team/serverless-resource-plugin, for example:plugins: - @hs-web-team/serverless-resource-policy - Within the
providerblock, add astagevariable:provider: stage: ${opt:stage, 'dev'} - Within a
customblock, add:custom: @hs-web-team/serverless-resource-policy: stage: ${self:provider.stage} privateStages: - dev - staging publicStages: - production netblocks: - 123.45.67.890/30 - 987.65.432.109
The
netblocksobject will contain the list of whitelisted IPs.
Full Example
# serverless.yml
service: my-service-name
plugins:
- @hs-web-team/serverless-resource-policy
provider:
stage: ${opt:stage, 'dev'}
custom:
@hs-web-team/serverless-resource-policy:
stage: ${self:provider.stage}
privateStages:
- dev
- staging
publicStages:
- production
netblocks:
- 123.45.67.890/30
- 987.65.432.109Contributing
Currently maintained by the lovely folks on HubSpot's Web Team, but we need your help. Please feel free to submit pull requests to add new functionality.