Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-44762

[enterprise-4.17] Issue in file installing/installing_platform_agnostic/installing-platform-agnostic.adoc

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • 4.17
    • Documentation
    • None
    • None
    • False
    • Hide

      None

      Show
      None

      Description of problem:

        Since OpenShift 4.12, Open Virtual Network (OVN) is the default CNI network provider [1]. OVN requires TCP ingress ports 6641 and 6642 to be open, as per OpenStack documentation [2].
      
      There is no listing for these two ports to be opened within the formal "Network connectivity requirements" section of the OpenShift "Installing a cluster on any platform" chapter for OCP 4.12 or above, even though this would need to be open by default.
      
      Specifically for ROSA/OSD/HCP products, the OpenShift installer will automatically create AWS Security Group ingress rules opening ports 6641 and 6642 for OVN.
      
      Please consider adding in an additional entry for ports 6641-6642 into the tables for "Network connectivity requirements" for documentation of currently supported OpenShift versions.
      
      [1] https://access.redhat.com/solutions/5843571
      [2] https://docs.redhat.com/en/documentation/red_hat_openstack_platform/17.1/html-single/configuring_red_hat_openstack_platform_networking/index#ovn-list-of-components_work-ovn

      Version-Release number of selected component (if applicable):

          4.12 and above

      How reproducible:

          N/A - missing documentation

      Steps to Reproduce:

          N/A - missing documentation   

      Actual results:

          N/A - missing documentation

      Expected results:

          N/A - missing documentation

      Additional info:

          This lack of documentation issue was observed by a Product Security Compliance team Systems Engineer performing a quarterly review of Security Group Rules for OpenShift on AWS clusters used by our Software-as-a-Service products, OSD, HCP, Quay.io and ACS CS. The engineer attempted to correlate the AWS Security Group Rules in the exported files with formal Red Hat documentation for auditing purposes, but found ports 6641-6642 were not listed as OCP required ports in any publicly accessible OpenShift guides.
      

              ocp-docs-bot OCP DocsBot
              rh-ee-broose Ben Roose
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: