Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-77040

Hypershift Konnectivity fails to add AWS ISO (classified) domains to ingress operator's NO_PROXY list

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.18, 4.19, 4.20
    • HyperShift
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • Important
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Hypershift Konnectivity fails to add AWS ISO (classified) domains to the ingress operator's NO_PROXY list.  This prevents necessary direct (not proxied) communication with endpoints in those namespaces.  The current list of cloud domains configured to be routed through the management cluster and not through Konnectivity can be found at https://github.com/openshift/hypershift/blob/main/support/konnectivityproxy/dialer.go#L462-L485.  The AWS ISO region domains that need to be added are:
      
      ".c2s.ic.gov"
      ".hci.ic.gov"
      ".sc2s.sgov.gov"    

      Version-Release number of selected component (if applicable):

          

      How reproducible:

          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

          

      Expected results:

          

      Additional info:

          

              Unassigned Unassigned
              rh-ee-cwigal Chad Wigal
              None
              None
              Yu Li Yu Li
              None
              Votes:
              1 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: