UpdatesExplore the release notes

Learn · Lesson 3 of 7 · 6 min

Lock down access

Make access easy to understand: name the machines that need to connect, choose the service, then review the result.

Start here: new networks include an allow-all rule.

Default ACL allows every node to reach every other node. Create your specific rules, then remove Default ACL to restrict access.

01 / GROUP YOUR MACHINES

Tags give your rules meaning.

Create tags in Access Control → Tags, then assign them on the Nodes page.

NodesExample
Developer laptopdev
Staging serverstaging
Production serverprod
02 / CREATE A RULE

Give development access to staging.

In Network Rules, create this rule. It allows HTTPS from devices tagged dev to devices tagged staging.

Create network ruleExample
Name
dev-to-staging
Source tags
dev
Destination tags
staging
Protocol / ports
TCP / 443
03 / REVIEW AND RESTRICT

See what you allowed.

Open Preview and review the sources, destinations and ports. Once the rules cover the access you need, delete Default ACL from Network Rules.

PreviewExample
dev
TCP · 443
staging

This rule grants no access to prod. Other allow rules still apply.

Preview shows your configuration. It does not test live traffic.

A few useful details

How rules combine. If any rule allows a packet, it passes. If none does, the node drops it. Rules have no order, priority or deny action.

Empty tags mean everyone. Leaving source or destination empty matches all nodes. Check these fields before saving.

Tags. Nodes can have several tags and match rules for any of them. Tags cannot be renamed: create a replacement, retag nodes, then delete the old tag.

Other services. For example, allow ci → registry on TCP 5000, sre → prod on TCP 22, or infra → prod on TCP 9090. Protocols include ALL, TCP, UDP and ICMP.

Changes are recorded. Rule creation, updates and deletion appear in the audit log.

Your rules describe the access you intend.

Next, give automated machines the right tags when they join.