Software Secure Workload
Activity Configure

Network Attack Surface of Secure Connector Client daemons

Customers are advised to install the Secure Connector client on a dedicated and isolated appropriately secured machine.

The Secure Connector client is a daemon running on the VM but has no ports open for listening. It is always the initiator of TCP connections and all communication between the Secure Connector client and the Secure Workload cluster is mutually authenticated and encrypted using TLS.

No inbound ports need to be opened on the VM firewall.

The machine should have firewall rules to allow outgoing connections only to the Secure Workload cluster and any external orchestrator API servers Secure Workload should be allowed to access.