5 ms·
Honestly I would never put any kind of internal server on the public Internet, make it reachable only via VPN to have a second line of defense.
by throwaway63467 3y ago
Honestly I would never put any kind of internal server on the public Internet, make it reachable only via VPN to have a second line of defense.
- andix 3y agoEspecially something like Gitlab might benefit a lot from external integrations that need to call the Gitlab API. It might be possible to whitelist exactly those requests, but also a bit cumbersome.
- dijit 3y agoGitlab is my favourite for running a codeforge: git.drk.sc For a highly secure environment, I agree to practice even more defensible tactics, but I think software out to be designed to survive the open web.
- pritambarhate 3y agoyes, especially if you are using self hosted gitlab for your company, you should always put it behind corporate VPN.