-
Feature Request
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
False
-
None
-
False
-
Not Selected
-
-
1. Proposed title of this feature request: Defined Port Ranges and ICMP Packet Types at Install Time
2. What is the nature and description of the request?
At install time have port ranges and ICMP Packet types be defined for OCP instead of using "All" settings in security rules in the cloud.
3. Why does the customer need this? (List the business requirements here)
Full context: SUPPORTEX-20907 and SUPPORTEX-20908
The customer is using a security scanner to secure their cloud resources. Customers has to make their clusters complaint to these third party security scanners for their security requirements. The default settings on some of the security groups in the cloud do not adhere and customer will need to modify these cloud security groups.
Customer is on AWS, but same concept will apply to Azure and GCP security groups though the implementation will differ.
4. List any affected packages or components.
Installer, Cluster API, Cloud Controllers