Habr•October 8, 2026•🇷🇺Translated from Russian

Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures

When an API gateway is placed in the DMZ and corporate security policy prohibits any connections from the DMZ into the internal LAN, the most obvious proxying pattern becomes impossible. Business requirements nevertheless demand that consumers receive synchronous HTTP responses, making a full rewrite of integration contracts prohibitively expensive.

Over the past year the team at Neoflex evaluated five architectural options on the NEOMSA APIM platform, which is built on WSO2 components including the gateway, Micro Integrator, and developer portal. Three patterns reached working laboratory environments, one underwent full load testing, and the remaining two were validated through architecture reviews and security approvals.

Variant 1: Custom request-reply over Kafka

Kafka is deployed in the DMZ. The gateway writes requests to a topic; an internal Micro Integrator instance connects outbound to consume them, invokes the target system, and publishes replies to a second topic. Because Kafka lacks native reply-to semantics, the team implemented correlation, partition-based routing, dead-letter handling, and offset management in approximately 2,500 lines of Java packaged as a custom mediator. The solution works but introduces significant maintenance obligations and removes centralized policy enforcement.

Variant 2: JMS request-reply with ActiveMQ Artemis

Replacing Kafka with ActiveMQ Artemis eliminates all custom code. Both sides use standard JMS mediators inside Micro Integrator. The broker handles correlation identifiers, message expiration, and selective consumption. Load tests demonstrated a sustained 50 requests per second with 95th-percentile latency near 100 ms. Limitations include the inability to stream large or unknown-size responses and the requirement for idempotency keys on state-changing operations.

Variant 3: Reverse HTTP via HAProxy

An internal node initiates a persistent HTTP/2 connection to the DMZ gateway; roles are then reversed so the gateway treats the tunnel as an upstream. No DMZ-to-LAN firewall rule is required, no custom code is written, and the call remains ordinary synchronous HTTP. The mechanism is still marked experimental in HAProxy 2.9+, requiring careful configuration of connection reuse and keep-alive parameters.

Variant 4 & 5: Dual gateways with narrow DMZ-to-LAN rule

When security permits a tightly scoped rule allowing mTLS-authenticated traffic on specific ports, two simpler topologies become viable: a single management plane controlling gateways in both zones, or two independent NEOMSA APIM installations. Both preserve full policy, throttling, and key-management capabilities in one administrative domain.

The decisive question for any organization facing the same constraint is whether a narrow DMZ-to-LAN firewall exception with mutual certificate authentication can be obtained. The answer immediately eliminates or validates half of the candidate architectures.

Related articles

Habr•Other

macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes

A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.

AntiMalware•Other

FSB in Chelyabinsk Region Proposes QR-Code Passports for Tracking Construction Materials to Combat Theft

The regional branch of Russia's Federal Security Service in Chelyabinsk has suggested introducing an electronic tracking system for construction materials using unique QR codes assigned to each batch. The initiative aims to reduce theft and fraud during the construction of social facilities by creating a verifiable digital record of material movement from supplier to site. According to official representative Tatyana Sosnina, the system would allow real-time comparison between ordered quantities, project documentation, and actual usage on site. This approach is expected to help customers and oversight bodies quickly identify discrepancies between procurement records and physical consumption. The proposal does not yet include any announced timelines or estimated implementation costs. Experts note that the effectiveness of such QR-based tracking will ultimately depend on the accuracy of data entry at every stage of the supply chain rather than on the codes themselves.

AntiMalware•Other

Russian Internet Services Hit by Outages After Drone Attack on Yandex Data Center in Sasovo

On October 8, multiple Russian websites and internal corporate systems experienced significant disruptions. Users reported issues accessing media outlets, transport services, and marketplaces, with many problems affecting internal company tools and professional platforms. Cian linked its website and app outage to an infrastructure partner incident, while developers A101, Granel, and Brusnika also faced temporary unavailability. T-Bank reported problems with its corporate messenger and email distributions, and similar internal system issues appeared at Ozon, Wildberries, and HSE. Astral warned of possible delays in electronic reporting and document management services. Yandex confirmed a fire at its Sasovo data center in Ryazan region following a drone attack, with no casualties but full shutdown of the facility. Experts note that not all complaints can be attributed to a single event due to varying scales of impact across companies.

Habr•Other

Tools Alone Won't Suffice: Building Systemic Kubernetes Security Across Hundreds of Clusters at Alfa-Bank

Alexander, lead of the K8S and cloud security department at Alfa-Bank, explains how the bank moved from fragmented tools and ad-hoc practices to a comprehensive process-driven security function covering more than 500 Kubernetes clusters. The approach centers on a threat lifecycle model that includes threat modeling, requirements definition, project expertise, auditing, risk assessment, platform operations, and SOC integration. A RACI matrix formalizes responsibilities across security, DevOps, AppSec Business Partners, and IT teams to ensure consistent execution at scale. Four specialized roles—an architect, analyst-engineer, auditor, and platform DevOps engineer—handle the workload that no single individual could manage. The bank emphasizes that commercial scanners and policies deliver value only when embedded in repeatable processes tied to a living threat model and clear accountability.