Skip to main content

Network Security

A defense-grade deployment treats the network as a primary control plane. This page covers perimeter controls (load balancer, WAF, firewall) and internal controls (NetworkPolicies, mTLS, segmentation).

Traffic flow & defense in depth​

Traffic flow & defense in depth
Users / Clients
Load BalancerF5 · Citrix · MetalLB
WAFOWASP CRS · F5 ASM
Perimeter Firewall
Ingress RouterTLS termination
OpenShift · segmented namespaces
Frontend pods
NetworkPolicy
Backend pods
OpenBao VMsFW 8200
PostgreSQL VMsFW 5432

Users pass through the load balancer, WAF, and perimeter firewall to the Ingress Router; inside segmented OpenShift namespaces the frontend reaches the backend over a NetworkPolicy, which in turn reaches OpenBao and PostgreSQL through the firewall.

Load balancing​

EnvironmentRecommended load balancer
Bare-metal OpenShiftMetalLB (L2/BGP) in front of the Ingress Router
Enterprise datacenterF5 BIG-IP LTM, Citrix ADC, or existing hardware LB
VMware / OpenStackPlatform LB (NSX ALB, Octavia) or external hardware LB

Guidance:

  • Load-balance across all Ingress Router replicas for HA; health-check the router endpoints.
  • Terminate or pass-through TLS depending on whether the WAF needs to inspect payloads (see below).
  • Preserve client source IPs (X-Forwarded-For / PROXY protocol) for audit logging.

Web Application Firewall (WAF)​

A WAF inspects HTTP(S) traffic for application-layer attacks (OWASP Top 10).

OptionNotes
ModSecurity + OWASP Core Rule Set (CRS)Open-source, deployable on-prem / air-gap
F5 Advanced WAF (ASM)Enterprise, integrates with BIG-IP LTM
Citrix Web App FirewallEnterprise
Imperva / Fortinet FortiWebEnterprise appliances

Recommended baseline:

  • Enable OWASP CRS in blocking mode after a short tuning period.
  • Enforce request size limits, rate limiting, and geo/IP allow-lists where applicable.
  • Forward WAF logs to your SIEM (see Compliance & Audit).

TLS everywhere​

  • External: TLS 1.2+ (prefer TLS 1.3) at the load balancer / Ingress Router. Use certificates from your enterprise/internal CA — fine for air-gapped sites.
  • Internal: service-to-service traffic is encrypted; the backend reaches OpenBao only over mutually authenticated (mTLS) channels.
  • Cipher policy: restrict to strong ciphers; the OpenShift IngressController tlsSecurityProfile can be set to Intermediate or Modern, or to a custom FIPS-compliant profile for defense environments.
# Enforce a modern TLS profile on the Ingress Router
apiVersion: operator.openshift.io/v1
kind: IngressController
metadata:
name: default
namespace: openshift-ingress-operator
spec:
tlsSecurityProfile:
type: Modern

North-south firewall rules​

These are the perimeter flows that must be permitted; deny everything else.

#SourceDestinationPort/ProtoPurpose
1ClientsLoad balancer VIP443/TCPUser access (HTTPS)
2LBIngress Router443/TCPForward to cluster
3AdminsOpenShift API6443/TCPCluster administration
4Worker nodesOpenBao VMs8200/TCPSecret retrieval
5Worker nodesPostgreSQL VMs5432/TCPDatabase
6ArgoCDGitLab443/TCP, 22/TCPGitOps source
7Cluster / VeleroObject storage443/TCPBackups
8OpenBao VMsHSMper vendorRoot of trust (optional)
9Mirror registryCluster443/TCPAir-gapped image pulls

East-west microsegmentation (NetworkPolicies)​

Inside the cluster, enforce a default-deny posture and allow only required flows. This contains lateral movement.

# Default deny all ingress in the duokey namespace
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-ingress
namespace: duokey
spec:
podSelector: {}
policyTypes: ["Ingress"]
---
# Allow only the frontend to reach the backend API
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-frontend-to-api
namespace: duokey
spec:
podSelector:
matchLabels: { app: duokey-api }
policyTypes: ["Ingress"]
ingress:
- from:
- podSelector:
matchLabels: { app: duokey-frontend }
ports:
- protocol: TCP
port: 8080

Service mesh & mTLS (optional)​

For zero-trust east-west security, deploy Red Hat OpenShift Service Mesh (Istio) to enforce strict mTLS between all workloads, with fine-grained authorization policies and per-service telemetry.

Network segmentation (VLANs)​

Segment the supporting infrastructure onto isolated VLANs:

VLANPurpose
ApplicationOpenShift worker/ingress traffic
Backend / dataPostgreSQL, Redis, storage
SecureOpenBao and HSM (most restricted)
ManagementOut-of-band / admin access
Air-gap

The entire architecture can operate with no outbound internet access. Use an internal mirror registry for images and keep the IdP, secret manager, and HSM fully on-premise.