Data Security
A newly installed Hydrolix cluster comes with centralized user authentication, a wide array of support for TLS, and encrypted data at rest.
Unified auth⚓︎
Each Hydrolix cluster can be configured to support Single Sign-On (SSO) and apply different access restrictions for users.
- Authentication and Authorization - overview of auth systems
- Account Types - local and SSO users, service accounts, administrative accounts
- Account Permissions (RBAC) - account-level access controls; Role-Based Access Controls
- User Authentication - how to authenticate and use tokens for services
Network security⚓︎
Hydrolix supports multiple load balancer choices, defaulting to a public IP load balancer, and optional network layer access control lists (ACLs) enforced in two places.
- The external load balancer enforces
ip_allowlistbefore traffic ever reaches the cluster. - The Traefik reverse proxy requires client IP preservation. It enforces the
traefik_ip_allowlistACL and can exempt specific services HTTP route or port.
Clusters can require TLS communication between end users and published services. See Enable TLS for different ways to provision certificates in a cluster. Hydrolix strongly recommends using TLS to secure communications.
---
title: Typical Load Balancer, Reverse Proxy, and TLS
config:
themeVariables:
fontSize: 18px
flowchart:
padding: 20
---
flowchart LR
classDef default stroke:#00A99D,stroke-width:2px
lb[External
Load
Balancer]
subgraph cluster[Cluster]
subgraph traefik-replicas[Traefik Reverse Proxy]
traefik[Traefik]
traefikN[Traefik]
end
subgraph Services
intake[Intake Head]
configapi[Config API]
qhead[Query Head]
end
end
client[application
client]
client == TLS ==> lb
lb == TLS ==> traefik
lb -. supports
replicas .-> traefikN
traefik -- plain --> intake
traefik -- plain --> configapi
traefik == TLS ==> qhead
classDef nodegroup fill:none,stroke:#8B9FAD,stroke-width:2px,stroke-dasharray:5 4,color:#4A5F73
class cluster,traefik-replicas,Services nodegroup
- The client's IP is always available to the external load balancer. See Configure IP Access to limit all access to a cluster's services using tunable
ip_allowlist. - When preserve client IP is used, the client's IP is available to the Traefik reverse proxy and it can enforce service-aware network ACLs. See Configure Traefik IP Allowlist to limit client access by HTTP route or port using tunable
traefik_ip_allowlist. - For applications that don't require custom TLS server termination, the TLS handshake and connection lands on the Traefik reverse proxy service and the plaintext HTTP request passes through to the service.
Load balancer choices⚓︎
Hydrolix supports the following load balancers using the traefik_service_type variable:
| Name | identifier | Behavior |
|---|---|---|
| Public load balancer | public_lb |
A load balancer using a routable public IP address |
| Private load balancer | private_lb |
A load balancer using a private IP in the same subnet as the Kubernetes nodes |
| Cluster IP | cluster_ip |
No load balancer at all: you can only access your cluster from within your Kubernetes cluster. |
| Node port | node_port |
A custom load balancer provided externally |
Depending on your usage and use case you might want a publicly addressable cluster or a private one.
Cluster-initiated traffic⚓︎
Hydrolix clusters securely retrieve data from object storage with token-based authentication over TLS. The data remains accessible only in the Virtual Private Cloud (VPC) hosting the Kubernetes deployment, isolating it from external networks.
Encrypt data at rest⚓︎
For AWS, Google Cloud, and Azure, Hydrolix uses cloud storage layers which encrypt data at rest by default. For more information, see the platform documentation:
Encrypt data at rest to ensure your data storage layer is secure and can't be accessed without authorization.
Object storage access credentials⚓︎
To connect to data storage layers, Hydrolix requires a service account or a secret key for interacting with the object storage system.
Use a service account or secret key to control access so only your Hydrolix cluster can access your storage layers.
Hydrolix clusters use a cache that stores metadata to disk. This cache is managed by your cloud storage layer provider, and thus is encrypted.