Skip to main content
This is feature is only available if you are on the Enterprise tier or above. See Astro Plans and Pricing.
You can restrict which IP addresses or IP address ranges can access the Astro service for your specific Organization. By default, Astro allows users to access their Organization from unsecured networks. However, by creating an IP access list, if your organization uses a VPN or other mechanism that limits the IP addresses your users might have, you can restrict access to Astro based on the IP addresses that you define in the Astro UI. After you enable the IP access list, users and user-privileged resources can only interact with Astro while using a network with a permitted IP address, whether by using the Astro UI or programmatically with Astro API or Airflow API requests. By default, Astro matches the IP address of the end user’s client. If you route Astro traffic through a forward proxy or secure tunnel, see Accept a proxy or tunnel egress IP address.

Prerequisites

  • Organization Owner permissions

Set up IP Access list

  1. In the Astro UI, go to Settings, then in the Security section, click IP Access List.
  2. Click + New IP Address Range.
  3. Add the IP address range or ranges in CIDR format, and click Add Address Range
You must make sure that you include critical services in your IP range. These include:
  • Make sure the first IP range you add is inclusive of the IP you are currently using, or you will be locked out of your Astro Organization.
  • You must include the IP address of your identity provider (IdP), if you have one, or it will also be locked out.

Accept a proxy or tunnel egress IP address

If you route Astro traffic through a forward proxy or secure tunnel (such as Zscaler), each request arrives with two source IP addresses: the IP address of the end user’s client and the public egress IP address of the proxy or tunnel. By default, Astro checks only the client IP address against your IP access list, so allowlisting your proxy’s egress ranges on their own doesn’t grant your users access. Turn on Proxy-Aware IP Allowlisting so that Astro also accepts the egress IP address as a valid match. Astro then allows a request when either the client IP address or the egress IP address falls within an allowed range. This setting is additive, so turning it on can only grant access. It never blocks a user who can already sign in.
  1. In the Astro UI, go to Settings, then in the Security section, click IP Access List.
  2. Turn on Proxy-Aware IP Allowlisting.
Proxy-Aware IP Allowlisting doesn’t add any addresses to your IP access list. You must still add the egress IP address ranges of your proxy or tunnel in CIDR format for Astro to match requests against them.

Restore access

Because the IP Access List limits access to the Astro UI only to specific IP addresses, you can’t access the Astro UI if you’re not connected to a corresponding VPN or authorized network. To restore access for a user that is blocked, an Organization Owner needs to either:
  • Disable the IP Access list setting by deleting the list or
  • Add the specific blocked user’s IP address to the IP Access list.
If you disable the IP Access List setting to resolve the user’s access issue temporarily, remember to enable the setting again to maintain the IP address restrictions.

Enhanced Support Access bypass

Enhanced Support Access is enabled by default for all Organizations to ensure faster, more effective assistance from the Astronomer Support team. It grants Read-only Admin access to your Organization’s details. If you have IP Access List enabled, Enhanced Support Access permits Astronomer Support to bypass the IP restriction and allows Astronomer Support to view your Organization details. Support can’t make any changes to your Organization or resources. See Enhanced Support Access for information about the permission scope and how to disable the feature.