Hosts, Services and Access¶
This page lists the logical hosts and services that make up the example environment, along with who is expected to have access to each.
- Application servers
- Accessed by the platform team via a bastion host
- Direct SSH from the public internet is disabled
- Database
- Accessed only from the application layer's security group
- Administrative access requires a temporary, audited role assumption
- Monitoring stack
- Read access available to all engineers
- Write access limited to the platform team
Access requests for any of the above should follow the process described in the Security section of this documentation.