Review internet exposure of Ansible Tower

Restrict access to Ansible Tower’s management interface and API to required administrators.

Description

If Ansible Tower is directly reachable from the internet, the system managing automation credentials and jobs becomes a target for external attacks. Reachability depends on routing, proxies, and firewalls as well as its address.

Potential impact

A compromised account or server can be used to misuse stored credentials and authorized automation jobs.

Remediation

Restrict access through a management network or authenticated VPN and close unnecessary public paths. Manage account permissions, multifactor authentication, and access records.

Examples

The examples compare public and private inventory addresses. Changing an inventory address alone does not move the server or block network access.

Before

text
[tower]
150.50.1.1

[automationhub]
automationhub.acme.org

[database]
database-01.acme.org

After

text
[tower]
172.27.0.2
172.27.0.3
172.27.0.4

References