Skip to main content

Restrict worker pool registration to specific IPs

You can now configure (via the UI and Terraform provider) an allowlist of IP ranges to restrict worker pool registrations from. Any registration attempts from outside of these specifically allowlisted IP ranges will be denied.

Status: ⬆️ Gathering votes2 comments

Log in to comment and vote

Comments2

  • Black Breeze

    •

    May 10, 2025

    Thanks for the suggestion! This could indeed be a helpful extra layer of security. That said, we’d love to understand the underlying concern a bit more clearly.

    What’s the specific risk or scenario you’re trying to guard against with IP restrictions at registration time? Given that each worker pool already requires a unique token, we’re curious what additional protection IP-based controls would provide in your environment.

    Are you trying to enforce that registration only happens from known networks (e.g., corporate VPCs)? Is the concern around credential misuse, auditability, or limiting setup to trusted infra? Or something else?

    If you’re open to sharing more about the trigger or goal behind the request, we’d love to better understand the job to be done—so we can evaluate whether IP restrictions are the best tool, or whether something different might get you there faster.

    • Orange Pond

      •

      May 27, 2025

      Hi Marcin!

      … limiting setup to trusted infra

      Exactly this. We would like to see additional controls that aim to protect unauthorized infrastructure from attempting to register to worker pools.

      In our use case, we have a single AWS account which is dedicated to hosting IaC automation infrastructure, including our private worker pool compute resources.

      An IP allowlist was the quickest/easiest additional layer that came to mind, though some form of certificate authentication would also be great.