Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-5487

Ingress Node Firewall should allow custom SSH rules


    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • openshift-4.14
    • Node
    • None
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

      Ingress Node Firewall has failsafe rules that prevent custom settings for SSH. 

      2. What is the nature and description of the request?

      While it makes perfect sense to have anti-lockout for API, etcd, Ingress and kubelet, SSH should be in control of the customer as this won't break OCP Cluster functionality.

      3. Why does the customer need this? (List the business requirements here)

      Customers which need to stay compliant to security regulations might need to block SSH access to all Nodes from within the Cluster (i.e. workload) as well. For maintenance, they need to keep it only open for specific networks/hosts. With the current approach and the zero-trust functionality we have in Ingress Node Firewall, this is not possible.

      4. List any affected packages or components.

      Ingress Node Firewall Operator

            gausingh@redhat.com Gaurav Singh
            rhn-support-agogala Arne Gogala
            0 Vote for this issue
            2 Start watching this issue
