Skip to content

Commit 2b21d49

Browse files
authored
Merge pull request #87723 from michaelryanmcneill/OSDOCS-13246
OSDOCS-13246: Clean up egress list for ROSA Classic/OSD-AWS
2 parents 57fbb95 + 32320e7 commit 2b21d49

File tree

1 file changed

+18
-56
lines changed

1 file changed

+18
-56
lines changed

modules/osd-aws-privatelink-firewall-prerequisites.adoc

Lines changed: 18 additions & 56 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,18 @@ endif::[]
6565
|443
6666
|Provides core container images.
6767

68+
|`cdn04.quay.io`
69+
|443
70+
|Provides core container images.
71+
72+
|`cdn05.quay.io`
73+
|443
74+
|Provides core container images.
75+
76+
|`cdn06.quay.io`
77+
|443
78+
|Provides core container images.
79+
6880
|`sso.redhat.com`
6981
|443
7082
|Required. The `https://console.redhat.com/openshift` site uses authentication from `sso.redhat.com` to download the pull secret and use Red{nbsp}Hat SaaS solutions to facilitate monitoring of your subscriptions, cluster inventory, chargeback reporting, and so on.
@@ -77,10 +89,6 @@ endif::[]
7789
|443
7890
|Provides core container images.
7991

80-
|`openshift.org`
81-
|443
82-
|Provides {op-system-first} images.
83-
8492
|`registry.access.redhat.com`
8593
|443
8694
|Hosts all the container images that are stored on the Red{nbsp}Hat Ecosytem Catalog. Additionally, the registry provides access to the `odo` CLI tool that helps developers build on OpenShift and Kubernetes.
@@ -105,50 +113,33 @@ endif::[]
105113
|443
106114
|Provides core container images as a fallback when quay.io is not available.
107115

108-
|`.q1w2.quay.rhcloud.com`
109-
|443
110-
|Provides core container images as a fallback when quay.io is not available.
111-
112-
|`www.okd.io`
113-
|443
114-
|The `openshift.org` site redirects through `www.okd.io`.
115-
116-
|`www.redhat.com`
117-
|443
118-
|The `sso.redhat.com` site redirects through `www.redhat.com`.
119-
120-
|`aws.amazon.com`
121-
|443
122-
|The `iam.amazonaws.com` and `sts.amazonaws.com` sites redirect through `aws.amazon.com`.
123-
124116
|`catalog.redhat.com`
125117
|443
126118
|The `registry.access.redhat.com` and `https://registry.redhat.io` sites redirect through `catalog.redhat.com`.
127119

128-
|`dvbwgdztaeq9o.cloudfront.net` ^[1]^
120+
|`oidc.op1.openshiftapps.com`
129121
|443
130122
|Used by ROSA for STS implementation with managed OIDC configuration.
131123

132124
ifdef::fedramp[]
133125
|`time-a-g.nist.gov`
134-
|123 ^[2]^
126+
|123 ^[1]^
135127
|Allows NTP traffic for FedRAMP.
136128

137129
|`time-a-wwv.nist.gov`
138-
|123 ^[2]^
130+
|123 ^[1]^
139131
|Allows NTP traffic for FedRAMP.
140132

141133
|`time-a-b.nist.gov`
142-
|123 ^[2]^
134+
|123 ^[1]^
143135
|Allows NTP traffic for FedRAMP.
144136
endif::fedramp[]
145137
|===
146138
+
147139
[.small]
148140
--
149-
1. The string of alphanumeric characters before `cloudfront.net` could change if there is a major cloudfront outage that requires redirecting the resource.
150141
ifdef::fedramp[]
151-
2. Both TCP and UDP ports.
142+
1. Both TCP and UDP ports.
152143
endif::fedramp[]
153144
--
154145
+
@@ -174,10 +165,6 @@ endif::fedramp[]
174165
|443
175166
|Required for telemetry and Red{nbsp}Hat Insights.
176167

177-
|`cloud.redhat.com/api/ingress`
178-
|443
179-
|Required for telemetry and Red{nbsp}Hat Insights.
180-
181168
|`observatorium-mst.api.openshift.com`
182169
|443
183170
|Required for managed OpenShift-specific telemetry.
@@ -259,11 +246,7 @@ Alternatively, if you choose to not use a wildcard for Amazon Web Services (AWS)
259246

260247
|`mirror.openshift.com`
261248
|443
262-
|Used to access mirrored installation content and images. This site is also a source of release image signatures, although the Cluster Version Operator (CVO) needs only a single functioning source.
263-
264-
|`storage.googleapis.com/openshift-release` (Recommended)
265-
|443
266-
|Alternative site to mirror.openshift.com/. Used to download platform release signatures that are used by the cluster to know what images to pull from quay.io.
249+
|Used to access mirrored installation content and images. This site is also a source of release image signatures.
267250

268251
|`api.openshift.com`
269252
|443
@@ -320,27 +303,6 @@ OR
320303
|The SFTP server used by `must-gather-operator` to upload diagnostic logs to help troubleshoot issues with the cluster.
321304
|===
322305

323-
. Allowlist the following URLs for optional third-party content:
324-
+
325-
[cols="6,1,6",options="header"]
326-
|===
327-
|Domain | Port | Function
328-
|`registry.connect.redhat.com`
329-
| 443
330-
| Required for all third-party-images and certified operators.
331-
332-
|`rhc4tp-prod-z8cxf-image-registry-us-east-1-evenkyleffocxqvofrk.s3.dualstack.us-east-1.amazonaws.com`
333-
| 443
334-
| Provides access to container images hosted on `registry.connect.redhat.com`
335-
336-
|`oso-rhc4tp-docker-registry.s3-us-west-2.amazonaws.com`
337-
| 443
338-
| Required for Sonatype Nexus, F5 Big IP operators.
339-
|===
340-
341-
. Allowlist any site that provides resources for a language or framework that your builds require.
342-
. Allowlist any outbound URLs that depend on the languages and frameworks used in OpenShift. See link:https://access.redhat.com/solutions/2998411[OpenShift Outbound URLs to Allow] for a list of recommended URLs to be allowed on the firewall or proxy.
343-
344306
ifeval::["{context}" == "rosa-sts-aws-prereqs"]
345307
:!fedramp:
346308
:!rosa-classic-sts:

0 commit comments

Comments
 (0)