How to Redirect traffic into 403 error not wide-listed traffic on kubernetes cluster

Viewed 87

we have an application that allows only paid IP I have to redirect not paid IP into 403 pages. For each ingress, I have to provide a list of IP ranges. Have to find the way to redirect if a user is not whitelisted to the provided URL with 403 error. Is anyone has an idea how I can perform this task? Thanks! GKE kubernetes cluster

1 Answers

Istio have ipBlocks and remoteIpBlocks.

You can use it to allow or block access from single IPs, or IP ranges.

For example

apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
  name: ingress-policy
  namespace: istio-system
spec:
  selector:
    matchLabels:
      app: istio-ingressgateway
  action: ALLOW
  rules:
  - from:
    - source:
        remoteIpBlocks: ["1.2.3.4", "5.6.7.0/24"]

creates a rule to allow traffic from 1.2.3.4 and 5.6.7.0/24 IPs.
IPs outside this range receive HTTP 403 response.

Related