Network Security
A defense-grade deployment treats the network as a primary control plane. This page covers perimeter controls (load balancer, WAF, firewall) and internal controls (NetworkPolicies, mTLS, segmentation).
Traffic flow & defense in depth
Users pass through the load balancer, WAF, and perimeter firewall to the Ingress Router; inside segmented OpenShift namespaces the frontend reaches the backend over a NetworkPolicy, which in turn reaches OpenBao and PostgreSQL through the firewall.
Load balancing
| Environment | Recommended load balancer |
|---|---|
| Bare-metal OpenShift | MetalLB (L2/BGP) in front of the Ingress Router |
| Enterprise datacenter | F5 BIG-IP LTM, Citrix ADC, or existing hardware LB |
| VMware / OpenStack | Platform LB (NSX ALB, Octavia) or external hardware LB |
Guidance:
- Load-balance across all Ingress Router replicas for HA; health-check the router endpoints.
- Terminate or pass-through TLS depending on whether the WAF needs to inspect payloads (see below).
- Preserve client source IPs (X-Forwarded-For / PROXY protocol) for audit logging.
Web Application Firewall (WAF)
A WAF inspects HTTP(S) traffic for application-layer attacks (OWASP Top 10).
| Option | Notes |
|---|---|
| ModSecurity + OWASP Core Rule Set (CRS) | Open-source, deployable on-prem / air-gap |
| F5 Advanced WAF (ASM) | Enterprise, integrates with BIG-IP LTM |
| Citrix Web App Firewall | Enterprise |
| Imperva / Fortinet FortiWeb | Enterprise appliances |
Recommended baseline:
- Enable OWASP CRS in blocking mode after a short tuning period.
- Enforce request size limits, rate limiting, and geo/IP allow-lists where applicable.
- Forward WAF logs to your SIEM (see Compliance & Audit).
TLS everywhere
- External: TLS 1.2+ (prefer TLS 1.3) at the load balancer / Ingress Router. Use certificates from your enterprise/internal CA — fine for air-gapped sites.
- Internal: service-to-service traffic is encrypted; the backend reaches OpenBao only over mutually authenticated (mTLS) channels.
- Cipher policy: restrict to strong ciphers; the OpenShift
IngressControllertlsSecurityProfilecan be set toIntermediateorModern, or to a custom FIPS-compliant profile for defense environments.
# Enforce a modern TLS profile on the Ingress Router
apiVersion: operator.openshift.io/v1
kind: IngressController
metadata:
name: default
namespace: openshift-ingress-operator
spec:
tlsSecurityProfile:
type: Modern
North-south firewall rules
These are the perimeter flows that must be permitted; deny everything else.
| # | Source | Destination | Port/Proto | Purpose |
|---|---|---|---|---|
| 1 | Clients | Load balancer VIP | 443/TCP | User access (HTTPS) |
| 2 | LB | Ingress Router | 443/TCP | Forward to cluster |
| 3 | Admins | OpenShift API | 6443/TCP | Cluster administration |
| 4 | Worker nodes | OpenBao VMs | 8200/TCP | Secret retrieval |
| 5 | Worker nodes | PostgreSQL VMs | 5432/TCP | Database |
| 6 | ArgoCD | GitLab | 443/TCP, 22/TCP | GitOps source |
| 7 | Cluster / Velero | Object storage | 443/TCP | Backups |
| 8 | OpenBao VMs | HSM | per vendor | Root of trust (optional) |
| 9 | Mirror registry | Cluster | 443/TCP | Air-gapped image pulls |
East-west microsegmentation (NetworkPolicies)
Inside the cluster, enforce a default-deny posture and allow only required flows. This contains lateral movement.
# Default deny all ingress in the duokey namespace
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-ingress
namespace: duokey
spec:
podSelector: {}
policyTypes: ["Ingress"]
---
# Allow only the frontend to reach the backend API
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-frontend-to-api
namespace: duokey
spec:
podSelector:
matchLabels: { app: duokey-api }
policyTypes: ["Ingress"]
ingress:
- from:
- podSelector:
matchLabels: { app: duokey-frontend }
ports:
- protocol: TCP
port: 8080
Service mesh & mTLS (optional)
For zero-trust east-west security, deploy Red Hat OpenShift Service Mesh (Istio) to enforce strict mTLS between all workloads, with fine-grained authorization policies and per-service telemetry.
Network segmentation (VLANs)
Segment the supporting infrastructure onto isolated VLANs:
| VLAN | Purpose |
|---|---|
| Application | OpenShift worker/ingress traffic |
| Backend / data | PostgreSQL, Redis, storage |
| Secure | OpenBao and HSM (most restricted) |
| Management | Out-of-band / admin access |
The entire architecture can operate with no outbound internet access. Use an internal mirror registry for images and keep the IdP, secret manager, and HSM fully on-premise.