-
Story
-
Resolution: Done
-
Undefined
-
None
-
None
-
None
-
False
-
None
-
False
-
NEW
-
NEW
-
-
Currently the mounted kubeconfig API server points to external load balancer IP.
Instead, can use internal cluster service itself that is "kube-apiserver", since its running in control plane namespace. It avoids the network traffic going outside and again reaches the kube-apiserver running in the same namespace.
For this, need to use service-network-admin-kubeconfig instead of the external kubeconfig admin-kubeconfig.
Like its being used for ingress operator here https://github.com/openshift/hypershift/blob/main/control-plane-operator/controllers/hostedcontrolplane/ingressoperator/ingressoperator.go#L157