From 8b10044ca32383368921479e4b9302d41f6a843c Mon Sep 17 00:00:00 2001 From: Platform Automation Date: Thu, 8 Jan 2026 15:02:05 +0000 Subject: [PATCH] security: narrow internal ingress CIDR (JIRA-4521) --- main.tf | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/main.tf b/main.tf index 41bfd210..91f1a41b 100644 --- a/main.tf +++ b/main.tf @@ -67,6 +67,11 @@ module "shared_security_group" { # Customer API access configuration locals { api_customer_cidrs = { + newco_19 = { + cidr = "203.0.113.119/32" + name = "NewCo 19" + } + newco_18 = { cidr = "203.0.113.118/32" name = "NewCo 18" @@ -179,7 +184,7 @@ locals { } } - api_internal_cidr = "10.0.0.0/8" + api_internal_cidr = "10.0.0.0/16" # SECURITY HARDENING: Narrowed to VPC CIDR per audit findings api_domain = "signals-demo-test.demo" api_alert_email = "alerts@example.com" }