Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-77247

Documentation on firewall allowlist is incomplete

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 4.18.z, 4.19.z, 4.20.z, 4.21.z
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • Critical
    • None
    • All
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Documentation on firewall allowlist is incomplete    

      Version-Release number of selected component (if applicable):

      All    

      How reproducible:

      Always    

      Steps to Reproduce:

      1.  Review the latest documentation [1] on opening up firewall
      2.  We see `registry.redhat.io` as a URL to add
      3.  When you go to this URL, it redirects you to `console.redhat.com`
      4.  `console.redhat.com` is not documented anywhere
          
      [1] https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/installation_configuration/configuring-firewall#configuring-firewall_configuring-firewall

      Actual results:

      Customer wants to know if we need to add `console.redhat.com` and have we actually fully tested this as our most current documents do not have this URL.  Are there any additional other URLs that are missing in the docs?    

      Expected results:

      Documented URLs that have been both _validated and tested_ by Red Hat that the customer can use as an allowlist (whitelist) and re-tested and verified by us everytime a new OpenShift release is available    

      Additional info:

      Customers have to create allowlists/whitelists that are detailed to their firewall and DNS teams, which require a corporate change request that is usually done during after hours.  
      
      The information we provide needs to be tried and tested.  Please provide any Jira issues that are open where we validate this so we can also double check the URLs on the customers behalf.    

              ocp-docs-bot OCP DocsBot
              rh-ee-syangsao Sam Yangsao
              Gaoyun Pei Gaoyun Pei
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: