It should have been using a /32, not a /8 subnet, in order to only allow the akkounts VM(s) to use the API endpoints without further authorization.
kosmos-ejabberd
Sets up ejabberd with vhosts for kosmos.org (public server) and 5apps.com (private server).