Choose who can reach your index
IP rules decide which addresses may use your Opensolr Index, and for which part of it. A request from an address without a matching rule is refused, even with the right password.
What a rule is
- IP Address: one IPv4 address, like
203.0.113.10, orallfor every address. - Request Handler: the part of the index the address may use, picked from the handlers of your index. For example
/selectfor searches,/updatefor writes, or/for every handler.
A new index starts with one rule: all on /. Every address may use every handler, and the username and password still protect it.
Add a rule
- Open the index in the Control Panel and click Security.
- Under IP Restriction, type the IP Address, or
all. - Pick the Request Handler.
- Click Save.
Your rules are listed under the form. To remove one, click the delete icon on its row.
A common setup: all on /select, so every address may search, and your server's address on /, so only your server may write.
Good to know
- An index with no rules at all is not reachable from any address. The tab warns you about it.
allon/means no address limit: only the password protects the index.- The Solr Admin of the index stops working when you take away its handlers.
- How many rules an index can have depends on your plan. On the free plan: 1.
By API
Add a rule, list the rules and remove a rule from your own code.
Security pages
- Security overview
- HTTP Basic Auth
- IP restriction
- Two-factor authentication