From 515a14cf8db4df7b738e1082f6f2b6786ebe69fe Mon Sep 17 00:00:00 2001 From: Platform Automation Date: Thu, 12 Mar 2026 15:21:53 +0000 Subject: [PATCH] security: narrow internal ingress CIDR (JIRA-4521) --- main.tf | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/main.tf b/main.tf index ef8307a..981371b 100644 --- a/main.tf +++ b/main.tf @@ -67,6 +67,11 @@ module "shared_security_group" { # Customer API access configuration locals { api_customer_cidrs = { + newco_20 = { + cidr = "203.0.113.120/32" + name = "NewCo 20" + } + newco_19 = { cidr = "203.0.113.119/32" name = "NewCo 19" @@ -185,7 +190,7 @@ locals { } } - api_internal_cidr = "10.0.0.0/8" + api_internal_cidr = "10.0.0.0/16" # SECURITY HARDENING: Narrowed to VPC CIDR per audit findings api_domain = "signals-demo-test.demo" api_alert_email = "alerts@example.com" }