Checks whether an OceanBase tenant has Internet access enabled and whether 0.0.0.0/0 is contained in any whitelist of the tenant.
Scenarios
Adding 0.0.0.0/0 to a whitelist of an OceanBase tenant allows access from all IP addresses, which poses significant security risks. Exercise caution when you configure this setting.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
- If Internet access is not enabled for the OceanBase tenant, the evaluation result is Compliant. If Internet access is enabled for the OceanBase tenant but 0.0.0.0/0 is not contained in any whitelist of the tenant, the evaluation result is Complaint.
- If Internet access is enabled for the OceanBase tenant and 0.0.0.0/0 is contained in a whitelist of the tenant, the evaluation result is Incomplaint. For more information about how to fix this, see the "Incompliance remediation" section of this topic.
Rule details
| Item | Description |
| Rule name | oceanbase-public-and-any-ip-access-check |
| Rule identifier | oceanbase-public-and-any-ip-access-check |
| Tag | Public and Oceanbase |
| Automatic remediation | Not supported |
| Trigger type | Configuration change |
| Supported resource type | OceanBase tenant |
| Input parameter | None |
Incompliance remediation
Disable Internet access for the OceanBase tenant or delete 0.0.0.0/0 from the whitelists of the tenant. For more information, see Create and manage server groups.