Hi DataHub team, we want to try out DataHub and wo...
# getting-started
a
Hi DataHub team, we want to try out DataHub and would like to conduct a preliminary security review of the platform first. Do you have any documentation on the best practices for hardening the deployment (both the datahub components and dependencies) from a security perspective? We use GKE and are interested in learning how we can restrict traffic to only certain static IP addresses or internal network. I also want to point out that the default
datahub/datahub
user doesn't seem to be a good practice. Chrome immediately flags it. It would be good if you can document in the deployment instructions how to configure a different username/password so that it encourages better security practices when deploying to the cloud.
👍 2
b
Agree with this feedback - Thank you Jinlin! We've heard similar concerns from others around overriding the default datahub/datahub root user file. Also, we hear you on the documentation for security considerations. It's something we are actively thinking about cc @orange-night-91387
a
Thank you @big-carpet-38439! Look forward to seeing the security consideration documents.