You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制ServiceFabric集群访问,仅允许API Management的IP接入

Restricting Service Fabric Cluster Access to Only API Management IPs

Great question! Locking down your Service Fabric (SF) cluster so only API Management (APIM) can send traffic to it is a smart security move, and it’s totally achievable using Azure’s network security controls. Here’s a step-by-step breakdown to make this happen:

Key Background

Service Fabric clusters hosted on Azure rely on Network Security Groups (NSGs) to enforce IP-level access rules. NSGs act as a firewall for your cluster’s subnets/nodes, letting you allow or deny traffic based on IP, port, and protocol. Since you already use a load balancer for port restrictions, adding NSG rules will layer on the IP-based filtering you need.

Step 1: Get API Management’s Outbound IP Addresses

First, you need the public IPs that APIM uses to send outbound traffic to your SF cluster. You can grab these in two ways:

  • Azure Portal: Navigate to your APIM instance → Overview → Look for the "Outbound IP addresses" field (it’ll list all public IPs associated with your APIM service).
  • Azure CLI: Run this command (replace <apim-resource-group> and <apim-name>):
    az apim show --resource-group <apim-resource-group> --name <apim-name> --query "publicIpAddresses" --output tsv
    
    Note: If your APIM is deployed inside a virtual network, use the VNet’s address range instead of public IPs.

Step 2: Locate Your Service Fabric Cluster’s NSG

Your SF cluster’s node pools are linked to an NSG (usually created automatically when you provision the cluster). To find it:

  • Go to your SF cluster in the Azure Portal → Nodes → Select your node pool → Under "Settings", click "Network security group".
  • Alternatively, find the virtual machine scale set (VMSS) for your node pool, then check its network configuration for the associated NSG.

Step 3: Configure NSG Inbound Rules

Now you’ll set up rules to allow only APIM traffic and block everything else:

  1. Add an Allow Rule for APIM:

    • In the NSG’s "Inbound security rules" section, click "Add".
    • Fill in the details:
      • Priority: Set a high priority (e.g., 100) — this ensures it runs before default deny rules.
      • Name: Something like Allow_APIM_To_SF
      • Source: Select "IP Addresses" and paste the APIM IPs/ranges you collected.
      • Source port ranges: Leave as * (APIM can use any outbound port).
      • Destination: Select "Any" or your SF cluster’s subnet address range.
      • Destination port ranges: Enter the ports your SF cluster exposes for traffic (e.g., 80,443 for HTTP/HTTPS).
      • Protocol: Select TCP (or UDP if your service uses it).
      • Action: Allow
    • Save the rule.
  2. Ensure Default Deny for All Other Traffic:

    • The default NSG inbound rule (DenyAllInBound) has a low priority (65500), which means it will block all traffic not explicitly allowed by higher-priority rules. You don’t need to change this, but double-check it’s enabled to make sure non-APIM traffic gets blocked.

Step 4: Verify the Configuration

To confirm everything works as expected:

  • Test access from an IP not in your APIM list: Try hitting your SF cluster’s endpoint — it should be blocked (you’ll get a timeout or connection refused).
  • Test via APIM: Send a request through your APIM service to the SF cluster — it should succeed.

Bonus Tips

  • If your APIM scales out or changes IPs, remember to update the NSG rule with the new addresses.
  • For extra security, consider pairing this with APIM’s mutual TLS (mTLS) authentication to add another layer of validation for incoming traffic.

内容的提问来源于stack exchange,提问作者Seppe Goossens

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:56:06