MRS Clusters Have Specified Security Groups Attached
Rule Details
Parameter |
Description |
---|---|
Rule Name |
mrs-cluster-in-allowed-security-groups |
Identifier |
MRS Clusters Have Specified Security Groups Attached |
Description |
If an MRS cluster does not have any of the specified security groups attached, this cluster is non-compliant. |
Tag |
mrs |
Trigger Type |
Configuration change |
Filter Type |
mrs.mrs |
Rule Parameters |
mrsSecurityGroupsId: indicates a security group ID. This is an array type parameter. |
Application Scenarios
A security group is a collection of access control rules for MRS clusters that have the same security requirements and are mutually trusted. You can define different access control rules for a security group, and these rules take effect for all MRS clusters added to this security group. Security groups control the network traffic to and from MRS clusters in the following ways:
- Traffic filtering: You can configure security group rules to allow or deny traffic from specific IP addresses or IP address ranges. This helps prevent traffic from known malicious IP addresses.
- Port control: By specifying allowed ports, security groups can prevent access to idle or insecure services.
- Protocol restriction: Security groups can also control traffic based on different network protocols (such as TCP and UDP). This is useful for ensuring that only necessary communication types are allowed.
- Inbound and outbound rules: Inbound rules control which traffic can enter a cluster, while outbound rules control where the cluster can send data. This bidirectional control provides more comprehensive security protection.
Solution
Add your MRS cluster to a proper security group.
Rule Logic
- If your MRS cluster is not added to any specified security groups, this cluster is non-compliant.
- If your MRS cluster is added to a specified security group, this cluster compliant.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot