Network-level access: lock your MCP servers to trusted networks
Blog post from Speakeasy
Speakeasy has introduced a network-level access feature for its MCP servers, allowing organizations to restrict server access to trusted networks, enhancing security by limiting exposure to internal users only. This is achieved by setting an IP allowlist for custom domains, ensuring that only traffic from specified IPv4 addresses or CIDR ranges can reach the servers, while unwanted traffic is blocked at the ingress level. This approach leverages Kubernetes networking, applying the allowlist to both NGINX ingress and Envoy gateway paths, ensuring requests from outside the allowed network are refused with a 403 error before reaching the server. Organizations can configure network-level access at the domain settings, ensuring private servers remain accessible while maintaining security with no bypassing of the policy. This feature represents the first tier of network-level security for MCP, with further integrations planned, catering to the increasing demands of security teams.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 8 | 7,668 | 844 | 209 | +8% |
| Kubernetes | 1 | 2,168 | 322 | 107 | +10% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.