microsoft / microsoft/AzureTRE

Access Public Airlock Storage Accounts through Application Gateway

Open
#4,150 3 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

  • #4853 by @marrobi — closed without merging
story
Dominant language
Python
Stars
235
Forks
192
Avg merge
1d 23h
Merged PRs (30d)
13

Description

Description

As a TRE Researcher,
I want to upload/download airlock files through application gateway,
So that URLs used will be the "TRE" ones.

As an administrator / security officer,
I want to reduce the number of exposed endpoints in the solution.

Acceptance criteria

  • Uploads are done through appgw with existing tools (az cli, storage explorer, etc.)
  • Downloads are done through appgw with existing tools (az cli, storage explorer, etc.)
  • The application (UI and/or API) is able to provide those "external" links correctly
  • If everything works, public access to airlock's external storage accounts need to be blocked

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the Application Gateway and airlock external storage integration described in the acceptance criteria. Verify uploads and downloads through existing Azure tools, confirm that UI or API links use the TRE endpoints, and only then check that public access to the external storage accounts can be blocked.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, python
Domain
api, cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.