NIFCLOUD

Guidance on networking, access and operational settings for NIFCLOUD resources managed with Terraform.

Documentation

Article Path
NIFCLOUD DB security group has no description terraform/nifcloud/db_security_group_description_undefined
NIFCLOUD DNS verification TXT record remains terraform/nifcloud/dns_has_verified_record
NIFCLOUD ELB listener uses HTTP terraform/nifcloud/elb_listener_use_http
NIFCLOUD ELB uses the common private network terraform/nifcloud/elb_has_common_private
NIFCLOUD ELB uses HTTP terraform/nifcloud/elb_use_http
Review HTTP traffic through a NIFCLOUD load balancer listener terraform/nifcloud/load_balancer_listener_use_http
Review HTTP traffic through a NIFCLOUD load balancer terraform/nifcloud/load_balancer_use_http
Review the NIFCLOUD load balancer TLS policy ID terraform/nifcloud/load_balancer_use_insecure_tls_policy_id
Review the NIFCLOUD load balancer TLS policy name terraform/nifcloud/load_balancer_use_insecure_tls_policy_name
NIFCLOUD NAS security group has no description terraform/nifcloud/nas_security_group_description_undefined
NIFCLOUD NAS uses the common private network terraform/nifcloud/nas_instance_has_common_private
Review NIFCLOUD RDB backup retention terraform/nifcloud/db_does_not_have_long_backup_retention
NIFCLOUD RDB uses the common private network terraform/nifcloud/db_instance_has_common_private
NIFCLOUD router uses the common private network terraform/nifcloud/router_has_common_private
NIFCLOUD security group rule has no description terraform/nifcloud/computing_security_group_rule_description_undefined
NIFCLOUD security group has no description terraform/nifcloud/computing_security_group_description_undefined
NIFCLOUD instance uses the common private network terraform/nifcloud/computing_instance_has_common_private
Review all-address access in a NIFCLOUD NAS security group terraform/nifcloud/nas_security_group_has_public_ingress_sgr
Review all-address access in a NIFCLOUD RDB security group terraform/nifcloud/db_security_group_has_public_ingress_sgr
Review all-address access in NIFCLOUD computing security groups terraform/nifcloud/computing_instance_has_public_ingress_sgr
Review public access to a NIFCLOUD RDB instance terraform/nifcloud/db_has_public_access
Review the security-group association of a NIFCLOUD VPN gateway terraform/nifcloud/vpn_gateway_security_group_undefined
Review the security-group association of a NIFCLOUD router terraform/nifcloud/router_security_group_undefined
Review the security-group association of a NIFCLOUD instance terraform/nifcloud/computing_instance_security_group_undefined

Related pages24

NIFCLOUD DB security group has no description

Document the purpose of the database access group.

NIFCLOUD DNS verification TXT record remains

Remove temporary verification records after DNS zone registration.

NIFCLOUD ELB listener uses HTTP

Configure HTTPS and a certificate for public ELB listeners.

NIFCLOUD ELB uses the common private network

Restrict ELB internal connections to the required networks.

NIFCLOUD ELB uses HTTP

Encrypt traffic between external clients and the ELB.

Review HTTP traffic through a NIFCLOUD load balancer listener

Protect web traffic through the listener with TLS.

Review HTTP traffic through a NIFCLOUD load balancer

Apply actual TLS encryption to public web traffic.

Review the NIFCLOUD load balancer TLS policy ID

Check the TLS settings selected by the policy ID.

Review the NIFCLOUD load balancer TLS policy name

Choose a policy that excludes obsolete TLS versions and weak cipher suites.

NIFCLOUD NAS security group has no description

Document the purpose of the file-storage access group.

NIFCLOUD NAS uses the common private network

Restrict which servers can reach file storage.

Review NIFCLOUD RDB backup retention

Keep backups long enough to detect problems and recover.

NIFCLOUD RDB uses the common private network

Restrict database networking to the required clients.

NIFCLOUD router uses the common private network

Define which networks and routes the router should connect.

NIFCLOUD security group rule has no description

Record why the rule permits the traffic.

NIFCLOUD security group has no description

Document the security group’s purpose and intended users.

NIFCLOUD instance uses the common private network

Place servers requiring isolation on a dedicated Private LAN.

Review all-address access in a NIFCLOUD NAS security group

Allow network access only from servers and management addresses that need the file share.

Review all-address access in a NIFCLOUD RDB security group

Restrict database connections to required applications and management addresses.

Review all-address access in NIFCLOUD computing security groups

Restrict network access to management and internal services to required addresses and ports.

Review public access to a NIFCLOUD RDB instance

Check whether database public access is needed and which clients are actually allowed.

Review the security-group association of a NIFCLOUD VPN gateway

Manage security-group rules to allow only required VPN peers and traffic.

Review the security-group association of a NIFCLOUD router

Manage the router’s security group and traffic paths according to its role.

Review the security-group association of a NIFCLOUD instance

Check the instance’s security-group association and allowed traffic against its role.