Product · IP and SSH key registry

IP and SSH key registry: who has which address and key, per environment.

Each person registers their IP addresses and SSH public keys. You decide which apply to which environment. Your firewall and servers read the result, so a rule always has a name next to it.

production9 ips · 6 keys
ENTRYOWNERLABEL
83.84.12.9m.vosoffice
145.53.201.77a.khanhome
SHA256:q7Kd…Lm0j.berglaptop
SHA256:Zx91…Pa4a.khanci runner
31.20.166.4p.smitleft · remove
How it works

People own entries. Environments pick from them.

01

Everyone registers their own

Each person adds their IP addresses (office, home) and SSH public keys (laptop, CI runner) with a short label. When a home IP changes, they update it themselves. The entry stays attached to the person.

AKa.khan
ip145.53.201.77 · homeip83.84.12.9 · officesshSHA256:Zx91…Pa4 · ci runnersshSHA256:Hw3e…R1n · laptop
02

Group by environment or server

Production, staging, the bastion host. Each one lists which entries apply. The CI runner's key goes to the deploy targets; a laptop key does not go to production. The list for each environment is what your infrastructure reads.

ENTRYPRODSTAGINGBASTION
a.khan · home●●○
a.khan · office●●●
a.khan · ci runner●●○
a.khan · laptop○●●
03

Your infrastructure reads the list

Copy it from the web app, export CSV or JSON, call the API, or use the Terraform data source to feed a security group or an authorized_keys file. OpsMinder keeps the list; your tools apply it.

data "opsminder_allowlist" "prod" {
environment = "production"
}
resource "aws_security_group_rule" "ssh" {
cidr_blocks = data.opsminder_allowlist.prod.cidrs
…
}
04

When someone leaves, the list changes

Remove the person and their entries are flagged, with the environments they were in. The team gets the message, the exports and data source stop including them, and the firewall follows on the next apply. Same when someone replaces a laptop.

OpsMinder#ops · Fri 09:00
p.smit was removed from the team. 2 entries to remove: 31.20.166.4 (production, bastion) and SSH key SHA256:Kd82…Qe7 (staging). Next terraform apply drops them.
Getting the list out

Four ways to read the registry.

Copy
A ready-to-paste list per environment, in CIDR or authorized_keys format.
Export
CSV or JSON, the whole registry or one environment.
API
For scripts and cron jobs. GET /allowlists/production
Terraform data source
Security groups and firewall rules follow the registry on every apply.

Put a name next to every rule.

Free for one developer. €1 per seat a month after that.