Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-9021

Azure Storage account created with IPI should restrict network access using virtual network rules

    • Quality / Stability / Reliability
    • None
    • None
    • None
    • Moderate
    • None
    • x86_64
    • None
    • None
    • Rejected
    • None
    • None
    • If docs needed, set a value
    • None
    • None
    • None
    • None
    • None

      Version:
      $ openshift-install version
      4.8.10

      Platform:
      Azure

      Please specify:

      • IPI

      What happened?
      An OCP4 cluster created on Azure comes by default with 2 Azure Storage Accounts

      • 1 starting with "cluster"
      • 1 starting with "imageregistry"

      Both are created with similar setup which is raising following security alert breaking our security compliancy:

      • Storage Access should restrict network access using virtual network rules

      Installer successfully deployed the clusters but today I see no customization possible in install-config to fix these security issues.

      What did you expect to happen?
      Storage account created should not raised security issues

      • Storage Access should restrict network access using virtual network rules

      How to reproduce it (as minimally and precisely as possible)?
      Deploy cluster on Azure using IPI
      Check storage accounts created but installer in Azure console

              tzivkovi@redhat.com Tori Zivkovic
              rh-support-fgrosjea Franck Grosjean
              Jinyun Ma Jinyun Ma
              Red Hat Employee
              None
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: