Environments ¶

This is a overview over the different environments and their available domains. Environments are sometimes also called clusters.

We also enumerate the external IPs used by the environments, so that you can provide them to services that require IP allow-listing.

Google Cloud Platform (GCP) ¶

dev-gcp ¶

Ingress domains ¶

domainaccessible fromnotes
ekstern.dev.nav.nointernetURLs containing /metrics, /actuator or /internal are blocked
intern.dev.nav.noNAV internal networks (including naisdevice)
ansatt.dev.nav.nointernet, only for authenticated humans on compliant devicesURLs containing /metrics, /actuator or /internal are blocked

See explanation for exposing application for more information.

External IPs ¶

  • 35.228.4.248
  • 34.88.219.93
  • 35.228.165.176

Kubectl access ¶

Kubectl access to the cluster is available through naisdevice. You can access all namespaces in the cluster, but you can only modify resources in your team's namespace.

Observability ¶

datadefault
logs (stdout)loki
auto-instrumentationgrafana-lgtm

prod-gcp ¶

Ingress domains ¶

domainaccessible fromnotes
nav.nointernetURLs containing /metrics, /actuator or /internal are blocked
intern.nav.noNAV internal networks (including naisdevice)
ansatt.nav.nointernet, only for authenticated humans on compliant devicesURLs containing /metrics, /actuator or /internal are blocked

See explanation for exposing application for more information.

External IPs ¶

  • 35.228.235.189
  • 35.228.12.134
  • 35.228.189.194

Kubectl access ¶

Kubectl access to the cluster is available through naisdevice. You can only read or modify resources in your team's namespace.

Observability ¶

datadefault
logs (stdout)loki
auto-instrumentationgrafana-lgtm

On-prem ¶

Warning

This is a legacy environment, and is not recommended for new workloads.

dev-fss ¶

Ingress domains ¶

domainaccessible fromdescription
intern.dev.nav.nonaisdevicedevelopment ingress for internal applications. Also available in dev-gcp, use this to ease migration
dev-fss-pub.nais.ioGCPSee How do I reach an application found on-premises from my application in GCP?

Kubectl access ¶

Kubectl access to the cluster is available through naisdevice. You can access all namespaces in the cluster, but you can only modify resources in your team's namespace.

Observability ¶

datadefault
logs (stdout)loki
auto-instrumentationgrafana-lgtm

prod-fss ¶

Ingress domains ¶

domainaccessible fromdescription
intern.nav.nonaisdeviceingress for internal applications (supersedes nais.adeo.no). Also available in prod-gcp, use this to ease migration. Requires JITA to onprem-k8s-prod
prod-fss-pub.nais.ioGCPSee How do I reach an application found on-premises from my application in GCP?

External IPs ¶

  • 155.55.65.50 (with webproxy)
  • 155.55.51.x/24 (without webproxy)

Kubectl access ¶

Kubectl access to the cluster is available through naisdevice with just in time access (jita). You can only read or modify resources in your team's namespace.

Observability ¶

datadefault
logs (stdout)loki
auto-instrumentationgrafana-lgtm