We would like to leverage ASGs on Bluemix Local. By design (CloudFoundry), ASG defines allow rules. This means that you can only add new rules to the existing ones.
On Bluemix Local, the default rules allow all traffic (all destinations, all protocols). As a consequence, there is no way to actually control which destinations are accessible from the apps. Adding new allow rules to the default allow all rule is useless.
The proposed solution to make it possible to leverage ASGs on Bluemix Local is to change the default rules to allow the traffic to the minimum (only what is required for Bluemix Local to run).
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Catherine - would you please tag the customers who have asked for this today?
More clarifications on the use case. Several Lines of Business have their apps hosted on the Bluemix Local Platform. An organization is assigned to each LoB. Each LoB can decide to have several spaces, one for test, one for integration, one for pre-production, etc. Apps need to reach backends (CICS, DBs, MQs on mainframe for example) hosted on corporate private network (outside of Bluemix, but still in private network). We want to make sure that Bluemix apps from LoB1 can access backends from LoB1 and only from LoB1, apps from LoB2 can access backends from LoB2 and only from LoB2, etc. We can even imagine than for a given LoB, the access to the pre-production backends is allowed only for the apps in the pre-production space (and not for the apps in the integration or test spaces).
Catherine - I seem to be missing the "why" here. What's the underlying use-case? Are they trying to restrict Local apps from connecting to other internal local apps and endpoints or external ones? If internal, why so? If external, why not do it with a proxy?