-
Bug
-
Resolution: Done-Errata
-
Undefined
-
4.10.z
-
None
-
No
-
False
-
-
-
Bug Fix
-
Done
Description of problem:
In an install where users bring their networks they also bring their own NSGs. However, the installer still creates NSG. In Azure environments using the rule [1] below, users are prohibited from installing cluster, as the apiserver_in rule has the rule set as 0.0.0.0[2]. Having a rule in place where the users could define this before install would allow them to set this connectivity without having the inbound access [1] - Rule: Network Security Groups shall not allow rule with 0.0.0.0/Any Source/Destination IP Addresses - Custom Deny [2] - https://github.com/openshift/installer/blob/master/data/data/azure/vnet/nsg.tf#L31
- blocks
-
OCPBUGS-15230 Allow installer to use existing Azure NSG during OpenShift IPI install
-
- Closed
-
- is cloned by
-
OCPBUGS-15230 Allow installer to use existing Azure NSG during OpenShift IPI install
-
- Closed
-
- links to
-
RHSA-2023:5006 OpenShift Container Platform 4.14.z security update
Since the problem described in this issue should be resolved in a recent advisory, it has been closed.
For information on the advisory (Important: OpenShift Container Platform 4.14.0 bug fix and security update), and where to find the updated files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2023:5006