Skip to main content

Illumio Core 23.5 Install, Configure, Upgrade

Outbound Connections

Outbound Connections

The outbound connections are required to access repositories.

rules-for-containerized-applications-3.png
Kubernetes and OpenShift

The rules you need to write are:

Example Ruleset

Scope

Application

Environment

Location

Risk Assessment

Development

Cloud

Intra-Scope Rule

Source

Destination

Service

Notes

Database (Role for Postgres Pods)

docker.io (IP List)

All Services

Once the database service gets discovered by the PCE, it becomes a virtual service object in the PCE, not a container workload. The source should be the role label of the virtual service, plus the "Use Virtual Service Only" option. The source in this example is the Web Pod. Use the Web Role label, which describes the Pod. Leave the Providing Service empty. Once the rule is saved, it will automatically populate with Derived from Source Virtual Service.