Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-3886

eGress Security Group for OCP using 0.0.0.0 during IPI AWS installation. Should use exact ports/IP details (if there is any requirements)

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Major Major
    • openshift-4.14
    • None
    • None
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

      eGress Security Group for OCP using 0.0.0.0 during IPI AWS installation. Should use exact ports/IP details (if there is any requirements)

      2. What is the nature and description of the request?

      eGress Security Group for OCP using 0.0.0.0 during IPI AWS installation. Should use exact ports/IP details (if there is any requirements)

      3. Why does the customer need this? (List the business requirements here)

      As per https://docs.openshift.com/container-platform/4.12/installing/installing_aws/installing-restricted-networks-aws-installer-provisioned.html

      This is introduced as OCP need to interact with multiple AWS services such as Route53, I AM service etc which needs internet access, however, my customer is using VPC endpoints as internet service is not available to them and also their security policy doesn't allow them to use SG 0.0.0.0

       

      4. List any affected packages or components.

      Security Breach

              mak.redhat.com Marcos Entenza Garcia
              rhn-support-skachhwa Sumeet Kachhwaha (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: