-
Epic
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
CAPO: new API for Security Groups
-
BU Product Work
-
5
-
False
-
None
-
False
-
Not Selected
-
To Do
-
OCPSTRAT-1429 - CAPO is functionally equivalent to what installer/terraform did pre 4.16
-
OCPSTRAT-1429CAPO is functionally equivalent to what installer/terraform did pre 4.16
-
ShiftStack Sprint 245, ShiftStack Sprint 246, ShiftStack Sprint 247, ShiftStack Sprint 248
Currently, CAPO is very opinionated when Security Groups are managed and over time too many rules were added without enough flexibility.
In OpenShift, we need more than the default rules for both the control plane & security group. Also, we need to replace Terraform to create additional Security Groups that will later be used by the machines.
We want to achieve this in CAPO.
Upstream issue: https://github.com/kubernetes-sigs/cluster-api-provider-openstack/issues/1752
Upstream KEP: https://github.com/kubernetes-sigs/cluster-api-provider-openstack/pull/1756
- is blocked by
-
OSASINFRA-3349 CAPO: refactor how ports are managed
- Closed