Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-183

Route Sharing for Management Clusters

XMLWordPrintable

    • Route Sharing for Management Clusters
    • BU Product Work
    • False
    • False
    • Done
    • OCPSTRAT-397 - HyperShift Metering & Cost Management
    • OCPSTRAT-397HyperShift Metering & Cost Management
    • 0% To Do, 0% In Progress, 100% Done
    • Undefined
    • 0
    • 0
    • 0

      Background

      Today, HyperShift exposes a public endpoint for cluster access which is accessible through a dedicated route. This can induce additional costs. 

      Goal

      Have all public traffic for a given mgmt cluster to go through a common router.  for public API endpoint access, we will want to prototype proxy_pass rewriting with our existing haproxy cfg and see what we learn so kubernetes.default.svc traffic works (needs proof of concept).

      For public API endpoint access, we will want to restrict the set of allowable cidrs and we think network policy per cluster namespace should be an option to facilitate that. 

            sjenning Seth Jennings
            azaalouk Adel Zaalouk
            Jie Zhao Jie Zhao
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: