Description
If Ansible Tower is directly reachable from the internet, the system managing automation credentials and jobs becomes a target for external attacks. Reachability depends on routing, proxies, and firewalls as well as its address.
Potential impact
A compromised account or server can be used to misuse stored credentials and authorized automation jobs.
Remediation
Restrict access through a management network or authenticated VPN and close unnecessary public paths. Manage account permissions, multifactor authentication, and access records.
Examples
The examples compare public and private inventory addresses. Changing an inventory address alone does not move the server or block network access.
Before
text
[tower]
150.50.1.1
[automationhub]
automationhub.acme.org
[database]
database-01.acme.org
After
text
[tower]
172.27.0.2
172.27.0.3
172.27.0.4