Cloud Foundry Security Groups and Custom Domains
In the SAP BTP Cloud Foundry environment, application security groups represent a collection of rules that control network traffic for applications. Developers use them to define which outbound connections an application is permitted to make, helping to enforce network-level security boundaries. By configuring these rules, operators can restrict or allow access to specific IP ranges and ports for applications running in the Cloud Foundry environment.
Tutorials that teach this
Docs explaining this concept
Prerequisites
- Concept SAP BTP Cockpit The concept name was not provided and the supplied source snippets do not define or describe a single, identifiable SAP developer concept — they cover a range of unrelated SAP BTP topics such as Kyma environment setup, Cloud Foundry org deletion, subaccount management, and service instances. A focused definition cannot be grounded solely in these sources without a clearly stated concept to define.
- Concept Cloud Foundry Environment Instance The concept provided is undefined, and the supplied sources cover general SAP Business Technology Platform (BTP) topics — such as the [Cloud Foundry environment](https://help.sap.com/docs/btp/sap-business-technology-platform/40a8f8f6f1724e0ca0fd2a8777f45504?locale=en-US&state=PRODUCTION&version=Cloud), the ABAP environment, and BTP account setup — without identifying a specific named concept to define. No definition can be accurately produced without a clearly stated concept, as fabricating one would go beyond what the provided sources support.
- Concept Cloud Foundry Org and Space Navigation The concept name is missing or undefined, so a precise definition cannot be produced. Based on the available sources, the closest identifiable concept relates to **SAP BTP Cloud Foundry Spaces**, which are organizational units within an SAP BTP subaccount where developers deploy and manage applications in the [Cloud Foundry runtime](https://help.sap.com/docs/btp/sap-business-technology-platform/81d0b4dcfbc84016b6b3c1465d4272f4?locale=en-US&state=PRODUCTION&version=Cloud). Developers use spaces to isolate workloads, control resource consumption through space quotas, and manage access by [adding space members and assigning roles](https://help.sap.com/docs/btp/sap-business-technology-platform/81d0b4dcfbc84016b6b3c1465d4272f4?locale=en-US&state=PRODUCTION&version=Cloud) at the space level via the SAP BTP Cockpit.
- Concept Roles in the Cloud Foundry Environment The concept name was not provided, so a precise definition cannot be generated from the available sources. Based on the sources, the closest identifiable concept appears to be a **Cloud Foundry Space** — a logical environment within a Cloud Foundry org on SAP BTP that developers use to deploy and manage applications and services. As described in [Managing Spaces](https://help.sap.com/docs/btp/sap-business-technology-platform/5209d55d8dd84228897112b0655d999b?locale=en-US&state=PRODUCTION&version=Cloud), spaces contain resources such as apps and service instances, and access is controlled by assigning roles to space members. Developers can manage space membership — including adding or removing users and their roles — directly in the SAP BTP cockpit, as outlined in [Delete Space Members](https://help.sap.com/docs/btp/sap-business-technology-platform/78b20cf8ae584498822dbd5c30e75b52?locale=en-US&state=PRODUCTION&version=Cloud).