Skip to main content

Allow setting IP allow list to limit access

As part of security compliance and requirements, it would be very helpful to be able to block access to the tenant based-on IP addresses

Status: ❌ Rejected1 comment

Log in to comment and vote

Comments1

  • Pink Octopus

    •

    Apr 1, 2025

    Hi Elad,

    Thanks for taking the time to share this request — we really appreciate your focus on security and compliance best practices.

    At the moment, we don't plan to implement tenant-level IP allow listing directly within Spacelift. That said, there are a couple of ways to achieve similar control using tools and policies that are likely already part of your setup:

    1. Login Policy Controls
      Spacelift's Login Policy system lets you enforce strict conditions around user authentication, which can include attributes passed from your Identity Provider (IdP). This provides a flexible and powerful way to gate access.

    2. IdP-Level IP Restrictions
      Many Identity Providers — such as Okta, Azure AD, and Auth0 — offer IP allow list capabilities directly at the SSO level. This is often the most secure and centralized way to control who can log in from where, and applies across all connected applications.

    3. Self-Hosting Option
      For teams that require deeper network-level controls, our self-hosted deployment offers full flexibility. You can run Spacelift within your own network perimeter, apply firewall rules, VPN restrictions, and other access policies as needed.

    We hope one of these approaches can meet your security needs.

    Thanks again for your feedback!

    Best regards,

    Spacelift Product Team