top | item 39160677

(no title)

frenchman99 | 2 years ago

Good reminder to always run internal services such as Gitlab behind a VPN which only trusted users have access to.

discuss

order

kdtsh|2 years ago

I really don’t understand why anyone would have their internal VC and CI/CD on the public Internet. This is exactly what VPNs are for.

INTPenis|2 years ago

Yes that's what saved us, and a few other things.

I work for a huge government owned telco and our networking guys are the best. They keep us server guys in line. So even though they did expose our Gitlab to an extent, for certain external projects and consultants, you still can't visit it from the internet freely.

And also we manage users in AD so there is no SMTP connection to even do password resets.

But we really need to enforce more 2FA, we've left it up to each project to enforce their own rules on 2FA.