Documentation

Enable security features

InfluxDB 2.7 provides optional security features that ensure your InfluxDB instance is secure in whatever environment it’s used in.

To enable all additional security features, use the hardening-enabled configuration option when starting InfluxDB.

Security features

Private IP Validation

Some Flux functions (to(), from(), http.post(), etc.), template fetching and notification endpoints can require InfluxDB to make HTTP requests over the network. With private IP validation enabled, InfluxDB first verifies that the IP address of the URL is not a private IP address.

IP addresses are considered private if they fall into one of the following categories:

  • IPv4 loopback (127.0.0.0/8)
  • RFC1918 (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
  • RFC3927 (169.254.0.0/16)
  • IPv6 loopback (::1/128)
  • IPv6 link-local (fe80::/10)
  • IPv6 unique local (fc00::/7)

Private IP considerations

If your environment requires that these authenticated HTTP requests be made to private IP addresses, omit the use of --hardening-enabled and consider instead setting up egress firewalling to limit which hosts InfluxDB is allowed to connect.


Was this page helpful?

Thank you for your feedback!


The future of Flux

Flux is going into maintenance mode. You can continue using it as you currently are without any changes to your code.

Read more

Now Generally Available

InfluxDB 3 Core and Enterprise

Start fast. Scale faster.

Get the Updates

InfluxDB 3 Core is an open source, high-speed, recent-data engine that collects and processes data in real-time and persists it to local disk or object storage. InfluxDB 3 Enterprise builds on Core’s foundation, adding high availability, read replicas, enhanced security, and data compaction for faster queries and optimized storage. A free tier of InfluxDB 3 Enterprise is available for non-commercial at-home or hobbyist use.

For more information, check out: