Source IP allowlists
Restrict exposed container ports to approved public source IPs or CIDR ranges where supported.
Combine IP allowlists, resource-group network locality, SSO-based forward authentication, hierarchical platform authorization, and audited service-principal access.
Capabilities
Restrict exposed container ports to approved public source IPs or CIDR ranges where supported.
Components in the same resource group and node can communicate according to platform rules without unnecessary WAN exposure.
For compatible HTTP workloads, Seemi validates Microsoft or Google SSO and at least L1 resource access before forwarding the request.
Grant L1, L2, or L3 access at tenant, resource-group, or component level, with higher hierarchy grants flowing downward.
Service principals receive explicit access like human users and use short-lived JWTs for supported API access.
Authorization, core configuration, and deployment changes are logged and visible to users with the required access.
Firewall rules restrict network reachability. Forward authentication adds an identity check for compatible web traffic. Applications may still need their own authorization controls.
MCP tools currently support static service-principal keys because many agent clients do not yet automate short-lived token refresh. Scope and authorization checks still apply.
Ready to move forward?