NSG: Allow only Cloudflare
published egress IPs
10.227.32.0/20
Deltek-CD OKE
(K8s API, nodes)
10.226.64.0/18
Shard OKE
(API, nodes, LB, file sharing)
10.226.128.0/18
10.225.128.0/18
Managed by Panorama (automated allow/remove)
- Phase 1: OCI NSG (restricted source CIDRs / security team controlled)
- Phase 2: Host-based proxy VM inside the CD VCN w/ host firewall -> forwards requests to OKE API endpoint
by dheraj