Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-8817

Proposal to amend or improve Load Balancing requirements for API and Ingress

XMLWordPrintable

    • Important
    • None
    • 1
    • Rejected
    • Unspecified
    • N/A
    • Release Note Not Required
    • Customer Facing

      Document URL:

      https://docs.openshift.com/container-platform/4.5/installing/installing_bare_metal/installing-bare-metal.html#network-topology-requirements

      https://docs.openshift.com/container-platform/4.5/installing/installing_vsphere/installing-restricted-networks-vsphere.html#network-topology-requirements

      https://docs.openshift.com/container-platform/4.5/installing/installing_ibm_z/installing-restricted-networks-ibm-z.html#network-topology-requirements

      Section Number and Name:

      • Network topology requirements

      Describe the issue:

      • Load balancing SSL Bridge/Re-encrypt termination is likely to break mTLS for the OAuth component, unless a mechanism is put in place to validate client certificates.

      Suggestions for improvement:

      • SSL Passthrough requirement for API and Ingress should prevail and SSL Bridge/Re-encrypt should be (likely, temporarily) removed, at least until a more fine-grained list of load balancing requirements (and supported SSL/TLS Terminations) is made available following this [0] parallel Documentation bug.


      [0] Lack of information on prerequisites for external load balancers - https://bugzilla.redhat.com/show_bug.cgi?id=1809694

              rhn-support-jbrigman James Brigman
              rhn-support-rsandu Robert Sandu
              Melvin Joseph Melvin Joseph
              Latha Sreenivasa Murthy Latha Sreenivasa Murthy
              Red Hat Employee
              Marc Curry
              Votes:
              0 Vote for this issue
              Watchers:
              19 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 10 weeks, 1 day
                  10w 1d