Updating Prisoner Content Hub WAF
Every so often, the Prisoner Content Hub require their WAF IP allowlist updating. This is a bespoke job and not fully #gitops
Note: When adding an IP range e.g.
/28, it must start with the first address in the range.10.0.0.50/28is not valid, however10.0.0.48/28is since it’s the start of the block.
- Log in to AWS Console
- Go to Parameter Store - ensure you’re in eu-west-2
- Search for “prisoner”
- Select the correct
ip-allow-listparameter store (per environment) - Add or remove the IP address from the JSON object and save
- Log in to Concourse
- Run the
infrastructure-accountplan pipeline - you should see theaws_wafv2_ip_sethave pending updates - Run the
infrastructure-accountapply pipeline - Confirm the changes by going to WAF & Shield, select Web ACLs, click on the correct environment, select Rules and search for the IP address.
This page was last reviewed on 24 November 2025.
It needs to be reviewed again on 24 May 2026
by the page owner #cloud-platform-notify
.
This page was set to be reviewed before 24 May 2026
by the page owner #cloud-platform-notify.
This might mean the content is out of date.