Skip to content

Data Security

A newly installed Hydrolix cluster comes with centralized user authentication, a wide array of support for TLS, and encrypted data at rest.

Unified auth⚓︎

Each Hydrolix cluster can be configured to support Single Sign-On (SSO) and apply different access restrictions for users.

Network security⚓︎

Hydrolix supports multiple load balancer choices, defaulting to a public IP load balancer, and optional network layer access control lists (ACLs) enforced in two places.

  • The external load balancer enforces ip_allowlist before traffic ever reaches the cluster.
  • The Traefik reverse proxy requires client IP preservation. It enforces the traefik_ip_allowlist ACL and can exempt specific services HTTP route or port.

Clusters can require TLS communication between end users and published services. See Enable TLS for different ways to provision certificates in a cluster. Hydrolix strongly recommends using TLS to secure communications.

---
title: Typical Load Balancer, Reverse Proxy, and TLS
config:
  themeVariables:
    fontSize: 18px
  flowchart:
    padding: 20
---
flowchart LR
  classDef default stroke:#00A99D,stroke-width:2px
  lb[External
     Load
     Balancer]

  subgraph cluster[Cluster]
    subgraph traefik-replicas[Traefik Reverse Proxy]
      traefik[Traefik]
      traefikN[Traefik]
    end
    subgraph Services
      intake[Intake Head]
      configapi[Config API]
      qhead[Query Head]
    end
  end

  client[application
         client]
  client == TLS ==> lb
  lb == TLS ==> traefik
  lb -. supports
        replicas .-> traefikN

  traefik -- plain --> intake
  traefik -- plain --> configapi
  traefik == TLS ==> qhead

  classDef nodegroup fill:none,stroke:#8B9FAD,stroke-width:2px,stroke-dasharray:5 4,color:#4A5F73
  class cluster,traefik-replicas,Services nodegroup
  • The client's IP is always available to the external load balancer. See Configure IP Access to limit all access to a cluster's services using tunable ip_allowlist.
  • When preserve client IP is used, the client's IP is available to the Traefik reverse proxy and it can enforce service-aware network ACLs. See Configure Traefik IP Allowlist to limit client access by HTTP route or port using tunable traefik_ip_allowlist.
  • For applications that don't require custom TLS server termination, the TLS handshake and connection lands on the Traefik reverse proxy service and the plaintext HTTP request passes through to the service.

Load balancer choices⚓︎

Hydrolix supports the following load balancers using the traefik_service_type variable:

Name identifier Behavior
Public load balancer public_lb A load balancer using a routable public IP address
Private load balancer private_lb A load balancer using a private IP in the same subnet as the Kubernetes nodes
Cluster IP cluster_ip No load balancer at all: you can only access your cluster from within your Kubernetes cluster.
Node port node_port A custom load balancer provided externally

Depending on your usage and use case you might want a publicly addressable cluster or a private one.

Cluster-initiated traffic⚓︎

Hydrolix clusters securely retrieve data from object storage with token-based authentication over TLS. The data remains accessible only in the Virtual Private Cloud (VPC) hosting the Kubernetes deployment, isolating it from external networks.

Encrypt data at rest⚓︎

For AWS, Google Cloud, and Azure, Hydrolix uses cloud storage layers which encrypt data at rest by default. For more information, see the platform documentation:

Encrypt data at rest to ensure your data storage layer is secure and can't be accessed without authorization.

Object storage access credentials⚓︎

To connect to data storage layers, Hydrolix requires a service account or a secret key for interacting with the object storage system.

Use a service account or secret key to control access so only your Hydrolix cluster can access your storage layers.

Hydrolix clusters use a cache that stores metadata to disk. This cache is managed by your cloud storage layer provider, and thus is encrypted.