apache / apache/cloudstack

Support ACL based on Domain/URL instead of IP

Open
#8,917 4 comments 0 reactions 0 assignees View on GitHub
complexity:complex component:advanced-networking component:networking component:vpc type:improvement
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

##### ISSUE TYPE

* Improvement Request

##### COMPONENT NAME

~~~
Improvement Request (Functionality)
~~~

##### CLOUDSTACK VERSION

~~~
4.19
~~~

##### CONFIGURATION

N/A

##### OS / ENVIRONMENT

N/A

##### SUMMARY

Note: This ticket is broken down as requested from the origianl post, https://github.com/apache/cloudstack/issues/8841

**Support ACL based on Domain/URL instead of IP**

- As a company, sometimes i would like to block access to specific sites (eg. google drive), which is based on domain.
- But i am unable to do so because, ACL Rules are based on explicitly specifying the IP address.
- Specifying the IP address/range of the intended website will be tedious and non-practical.

##### STEPS TO REPRODUCE

N/A

~~~
N/A
~~~

##### EXPECTED RESULTS

~~~
To be able to manage ACL Rules more easily for enterprise use cases.
~~~

##### ACTUAL RESULTS

~~~
Unable to effectively block access to certain sites using URL/Domain
~~~

Contributor guide

Open the contributing guide

Research direction

Start by reading the linked original issue 8841 and the existing ACL functionality in CloudStack. Define how domain/URL-based rules should be configured and enforced, then confirm the behavior supports blocking sites such as Google Drive and is covered by appropriate tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
networking, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.