OpenShift icon indicating copy to clipboard operation
OpenShift copied to clipboard

Configurable Egress IP

Open jboutaud opened this issue 3 years ago • 6 comments

In a private ARO cluster with UDR, as described at: https://learn.microsoft.com/en-us/azure/openshift/howto-create-private-cluster-4x#create-a-private-cluster-without-a-public-ip-address , provide the ability to configure EgressIP as described at: https://docs.openshift.com/container-platform/4.13/networking/ovn_kubernetes_network_provider/configuring-egress-ips-ovn.html

jboutaud avatar Oct 01 '21 18:10 jboutaud

That would actually be a great improvement, as we're currently making use for a pretty long time (since v3) of NS egressIPs on our IPI onPrem environment. We run special workloads which make connections to private resources outside the cluster protected by additional FWs, ACLs, etc. Those are currently limited in our platform to run only onPrem.

marcusne avatar May 08 '23 06:05 marcusne

This may be necessary for some use cases that we're evaluating to put into ARO (or ROSA or on-prem). I'm concerned to see that it has been moved from "Coming Soon" back into "Backlog (Committed Items)".

BenjaminNeale-Heritage avatar Jun 18 '23 22:06 BenjaminNeale-Heritage

This feature is necessary to ensure a secure cluster. In a standard private cluster you will route egress traffic to a firewall and without unique source IPs for namespaces you have to create firewall openings for the entire worker subnet. This means that if an attacker gets access to the worker node through privilege escalation then they will be able to use those firewall openings for further infiltration.

t-alt avatar Oct 03 '23 13:10 t-alt

Would love to see that feature available on ARO in 2024 asap. Unfortunately, I have already had to reject projects from using ARO because this essential feature for us is not yet available.

marcusne avatar Nov 28 '23 06:11 marcusne

Could someone please provide an update on when this feature will be introduced in ARO?

rhn-support-pmagotra avatar Dec 20 '23 16:12 rhn-support-pmagotra

I am commenting again for visibility.

rhn-support-pmagotra avatar Mar 15 '24 13:03 rhn-support-pmagotra