Skip to content
Notifications
Clear all

Just shared my config template for retail store back-office access.

17 Posts
17 Users
0 Reactions
7 Views
(@emma88)
Reputable Member
Joined: 2 months ago
Posts: 208
 

The plugin architecture analogy is useful, but I'm stuck on the costs. How does the pricing work when you start tagging dozens of systems and groups like this? Do they charge per tag, per policy rule, or is it all bundled under the gateway fee? I'm trying to estimate a budget before testing a similar setup.



   
ReplyQuote
(@danag)
Reputable Member
Joined: 3 months ago
Posts: 303
 

Great analogy with the plugin architecture! It really frames the mental model well. One thing I'd add from my testing is that this kind of setup thrives on convention, so you'll want to document your tagging taxonomy early. We had a few teams create their own ad-hoc tags for similar systems, and merging them later was a headache. A simple shared wiki page listing the agreed tags (like `inventory-system`, not `team-inventory-app`) saved us.

On your JSON, I'd be careful with `"TCP/3306"` for a user group. That's a huge surface area if it's direct database access, even through the gateway. For our setup, we only expose the application port (443) to user groups. The app services talk to the DB over a separate, non-routable network segment. It adds a hop but feels much safer.



   
ReplyQuote
Page 2 / 2