Skip to content

Commit 6e59529

Browse files
authored
Merge pull request #90409 from laubai/osdocs-11789-partial-revert-hcp-publish-delay
Partial revert of ROSA split for firewall prereqs
2 parents c3b27b0 + 507552c commit 6e59529

File tree

9 files changed

+58
-51
lines changed

9 files changed

+58
-51
lines changed

modules/osd-aws-privatelink-firewall-prerequisites.adoc

Lines changed: 7 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -4,28 +4,17 @@
44
// * rosa_install_access_delete_clusters/rosa_getting_started_iam/rosa-aws-prereqs.adoc
55
// * rosa_planning/rosa-sts-aws-prereqs.adoc
66

7-
ifeval::["{context}" == "rosa-sts-aws-prereqs"]
8-
:fedramp:
9-
:rosa-classic-sts:
10-
endif::[]
11-
ifeval::["{context}" == "aws-ccs"]
12-
:osd:
13-
endif::[]
14-
ifeval::["{context}" == "prerequisites"]
15-
:rosa-classic:
16-
endif::[]
17-
187
:_mod-docs-content-type: PROCEDURE
19-
ifdef::rosa-classic-sts[]
8+
ifdef::openshift-rosa[]
209
[id="rosa-classic-firewall-prerequisites_{context}"]
21-
= ROSA Classic
22-
endif::rosa-classic-sts[]
23-
ifndef::rosa-classic-sts[]
10+
= Firewall prerequisites for ROSA (classic architecture) clusters using STS
11+
endif::openshift-rosa[]
12+
ifdef::openshift-dedicated[]
2413
[id="osd-aws-privatelink-firewall-prerequisites_{context}"]
25-
= AWS firewall prerequisites
14+
= Firewall prerequisites
2615

2716
If you are using a firewall to control egress traffic from {product-title}, you must configure your firewall to grant access to the certain domain and port combinations below. {product-title} requires this access to provide a fully managed OpenShift service.
28-
endif::rosa-classic-sts[]
17+
endif::openshift-dedicated[]
2918

3019
ifdef::openshift-rosa[]
3120
[IMPORTANT]
@@ -261,15 +250,4 @@ Alternatively, if you choose to not use a wildcard for Amazon Web Services (AWS)
261250
|`sftp.access.redhat.com` (Recommended)
262251
|22
263252
|The SFTP server used by `must-gather-operator` to upload diagnostic logs to help troubleshoot issues with the cluster.
264-
|===
265-
266-
ifeval::["{context}" == "rosa-sts-aws-prereqs"]
267-
:!fedramp:
268-
:!rosa-classic-sts:
269-
endif::[]
270-
ifeval::["{context}" == "aws-ccs"]
271-
:!osd:
272-
endif::[]
273-
ifeval::["{context}" == "prerequisites"]
274-
:!rosa-classic:
275-
endif::[]
253+
|===

modules/rosa-hcp-firewall-prerequisites.adoc

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,9 +6,9 @@
66
//TODO OSDOCS-11789: Why is this a procedure and not a reference?
77

88
[id="rosa-hcp-firewall-prerequisites_{context}"]
9-
= Firewall prerequisites
9+
= Firewall prerequisites for {hcp-title}
1010

11-
* If you are using a firewall to control egress traffic from {product-title}, your Virtual Private Cloud (VPC) must be able to complete requests from the cluster to the Amazon S3 service, for example, via an Amazon S3 gateway.
11+
* If you are using a firewall to control egress traffic from {hcp-title-first}, your Virtual Private Cloud (VPC) must be able to complete requests from the cluster to the Amazon S3 service, for example, via an Amazon S3 gateway.
1212

1313
* You must also configure your firewall to grant access to the following domain and port combinations.
1414
//TODO OSDOCS-11789: From your deploy machine? From your cluster?
@@ -127,4 +127,4 @@ Your workload may require access to other sites that provide resources for progr
127127
|`oso-rhc4tp-docker-registry.s3-us-west-2.amazonaws.com`
128128
| 443
129129
| Optional. Required for Sonatype Nexus, F5 Big IP operators.
130-
|===
130+
|===

networking/network-verification.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ ifdef::openshift-dedicated[]
4141
* Egress is available to the required domain and port combinations that are specified in the xref:../osd_planning/aws-ccs.adoc#osd-aws-privatelink-firewall-prerequisites_aws-ccs[AWS firewall prerequisites] section.
4242
endif::openshift-dedicated[]
4343
ifdef::openshift-rosa[]
44-
* Egress is available to the required domain and port combinations that are specified in the xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites] section.
44+
* Egress is available to the required domain and port combinations that are specified in the xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites] section.
4545
endif::openshift-rosa[]
4646

4747
include::modules/automatic-network-verification-bypassing.adoc[leveloffset=+1]

rosa_architecture/rosa_policy_service_definition/rosa-policy-responsibility-matrix.adoc

Lines changed: 14 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -10,12 +10,15 @@ This documentation outlines Red{nbsp}Hat, Amazon Web Services (AWS), and custome
1010

1111
include::modules/rosa-policy-responsibilities.adoc[leveloffset=+1]
1212

13-
ifndef::openshift-rosa-hcp[]
1413
[role="_additional-resources"]
1514
.Additional resources
15+
ifdef::openshift-rosa[]
16+
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites for ROSA (classic architecture) clusters using STS]
17+
endif::openshift-rosa[]
18+
ifdef::openshift-dedicated[]
19+
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites]
20+
endif::openshift-dedicated[]
1621

17-
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites]
18-
endif::openshift-rosa-hcp[]
1922

2023

2124

@@ -32,12 +35,17 @@ include::modules/managed-cluster-notification-policy.adoc[leveloffset=+2]
3235
include::modules/rosa-policy-incident.adoc[leveloffset=+1]
3336
include::modules/rosa-policy-change-management.adoc[leveloffset=+1]
3437
35-
ifndef::openshift-rosa-hcp[]
3638
[role="_additional-resources"]
3739
.Additional resources
38-
39-
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites]
40+
ifdef::openshift-rosa-hcp[]
41+
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-hcp-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites for {hcp-title}]
4042
endif::openshift-rosa-hcp[]
43+
ifdef::openshift-rosa[]
44+
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites for ROSA (classic architecture) clusters using STS]
45+
endif::openshift-rosa[]
46+
ifdef::openshift-dedicated[]
47+
* xref:../../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites]
48+
endif::openshift-dedicated[]
4149
4250
include::modules/rosa-policy-security-and-compliance.adoc[leveloffset=+1]
4351
include::modules/rosa-policy-disaster-recovery.adoc[leveloffset=+1]

rosa_cluster_admin/rosa-cluster-notifications.adoc

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,5 +60,11 @@ include::modules/managed-cluster-remove-notification-contacts.adoc[leveloffset=+
6060
* Ensure that your cluster can access resources at `api.openshift.com`.
6161
// TODO: Include this xref once all of the files have been added to the ROSA HCP distro.
6262
ifndef::openshift-rosa-hcp[]
63-
* Ensure that your firewall is configured according to the documented prerequisites: xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites]
64-
endif::openshift-rosa-hcp[]
63+
* Ensure that your firewall is configured according to the documented prerequisites:
64+
ifdef::openshift-rosa[]
65+
** xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites for ROSA (classic architecture) clusters using STS]
66+
endif::openshift-rosa[]
67+
ifdef::openshift-dedicated[]
68+
** xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites]
69+
endif::openshift-dedicated[]
70+
endif::openshift-rosa-hcp[]

rosa_hcp/rosa-hcp-aws-private-creating-cluster.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ include::modules/rosa-additional-principals-overview.adoc[leveloffset=+1]
1616
include::modules/rosa-additional-principals-create.adoc[leveloffset=+2]
1717
include::modules/rosa-additional-principals-edit.adoc[leveloffset=+2]
1818

19+
//unclear on why this is here given this is a HCP assembly
1920
ifndef::openshift-rosa-hcp[]
2021
[id="next-steps_rosa-hcp-aws-private-creating-cluster"]
2122
== Next steps
@@ -26,7 +27,6 @@ xref:../rosa_install_access_delete_clusters/rosa-sts-config-identity-providers.a
2627
== Additional resources
2728

2829
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-hcp-firewall-prerequisites_rosa-sts-aws-prereqs[AWS PrivateLink firewall prerequisites]
29-
//* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS PrivateLink firewall prerequisites]
3030
* xref:../rosa_getting_started/rosa-sts-getting-started-workflow.adoc#rosa-sts-overview-of-the-deployment-workflow[Overview of the ROSA with STS deployment workflow]
3131
* xref:../rosa_install_access_delete_clusters/rosa-sts-deleting-cluster.adoc#rosa-sts-deleting-cluster[Deleting a ROSA cluster]
3232
* xref:../architecture/rosa-architecture-models.adoc#rosa-architecture-models[ROSA architecture models]

rosa_install_access_delete_clusters/rosa-aws-privatelink-creating-cluster.adoc

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,15 @@ include::modules/osd-aws-privatelink-config-dns-forwarding.adoc[leveloffset=+1]
2020
[role="_additional-resources"]
2121
== Additional resources
2222

23-
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS PrivateLink firewall prerequisites]
23+
ifdef::openshift-rosa-hcp[]
24+
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-hcp-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites for {hcp-title}]
25+
endif::openshift-rosa-hcp[]
26+
ifdef::openshift-rosa[]
27+
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites for ROSA (classic architecture) clusters using STS]
28+
endif::openshift-rosa[]
29+
ifdef::openshift-dedicated[]
30+
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[Firewall prerequisites]
31+
endif::openshift-dedicated[]
2432
* xref:../rosa_getting_started/rosa-sts-getting-started-workflow.adoc#rosa-sts-overview-of-the-deployment-workflow[Overview of the ROSA with STS deployment workflow]
2533
* xref:../rosa_install_access_delete_clusters/rosa-sts-deleting-cluster.adoc#rosa-sts-deleting-cluster[Deleting a ROSA cluster]
2634
* xref:../architecture/rosa-architecture-models.adoc#rosa-architecture-models[ROSA architecture models]

rosa_planning/rosa-cloud-expert-prereq-checklist.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -172,7 +172,7 @@ include::modules/mos-network-prereqs-min-bandwidth.adoc[leveloffset=+2]
172172
//TODO OSDOCS-11789: Are these things that your cluster needs access to, or your deploying machine needs access to?
173173
* Configure your firewall to allow access to the domains and ports listed in
174174
ifdef::openshift-rosa[]
175-
xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites].
175+
xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites].
176176
endif::openshift-rosa[]
177177
ifdef::openshift-rosa-hcp[]
178178
xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-hcp-firewall-prerequisites_rosa-hcp-prereqs[AWS firewall prerequisites]

rosa_planning/rosa-sts-aws-prereqs.adoc

Lines changed: 14 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ include::_attributes/attributes-openshift-dedicated.adoc[]
44
ifndef::openshift-rosa-hcp[]
55
:context: rosa-sts-aws-prereqs
66
[id="rosa-sts-aws-prereqs"]
7-
= Detailed requirements for deploying ROSA using STS
7+
= Detailed requirements for deploying ROSA (classic architecture) using STS
88
endif::openshift-rosa-hcp[]
99
ifdef::openshift-rosa-hcp[]
1010
:context: rosa-hcp-prereqs
@@ -55,9 +55,12 @@ include::modules/rosa-sts-aws-requirements-security-req.adoc[leveloffset=+2]
5555
[role="_additional-resources"]
5656
[id="additional-resources_aws-security-requirements_{context}"]
5757
.Additional resources
58-
ifndef::openshift-rosa-hcp[]
58+
ifdef::openshift-dedicated[]
5959
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites]
60-
endif::openshift-rosa-hcp[]
60+
endif::openshift-dedicated[]
61+
ifdef::openshift-rosa[]
62+
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-classic-firewall-prerequisites_rosa-sts-aws-prereqs[AWS firewall prerequisites]
63+
endif::openshift-rosa[]
6164
ifdef::openshift-rosa-hcp[]
6265
* xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-hcp-firewall-prerequisites_rosa-hcp-prereqs[AWS firewall prerequisites]
6366
endif::openshift-rosa-hcp[]
@@ -112,12 +115,14 @@ include::modules/mos-network-prereqs-min-bandwidth.adoc[leveloffset=+2]
112115

113116
// Keeping existing ID to prevent link breakage
114117
ifdef::openshift-rosa[]
115-
[id="osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs"]
116-
=== AWS firewall prerequisites
118+
//[id="osd-aws-privatelink-firewall-prerequisites_rosa-sts-aws-prereqs"]
119+
//=== AWS firewall prerequisites
117120

118-
If you are using a firewall to control egress traffic from your {product-title}, you must configure your firewall to grant access to the certain domain and port combinations below. {product-title} requires this access to provide a fully managed OpenShift service.
121+
//If you are using a firewall to control egress traffic from your {product-title}, you must configure your firewall to grant access to the certain domain and port combinations below. {product-title} requires this access to provide a fully managed OpenShift service.
119122

120-
include::modules/osd-aws-privatelink-firewall-prerequisites.adoc[leveloffset=+3]
123+
include::modules/osd-aws-privatelink-firewall-prerequisites.adoc[leveloffset=+2]
124+
// TODO HCP SPLIT - remove openshift-rosa from below condition when HCP docs are published
125+
include::modules/rosa-hcp-firewall-prerequisites.adoc[leveloffset=+2]
121126
endif::openshift-rosa[]
122127

123128
ifdef::openshift-rosa-hcp[]
@@ -130,9 +135,11 @@ ifdef::openshift-rosa[]
130135
* xref:../support/remote_health_monitoring/about-remote-health-monitoring.adoc#about-remote-health-monitoring[About remote health monitoring]
131136
endif::openshift-rosa[]
132137

138+
[discrete]
133139
== Next steps
134140
* xref:../rosa_planning/rosa-sts-required-aws-service-quotas.adoc#rosa-required-aws-service-quotas_rosa-sts-required-aws-service-quotas[Review the required AWS service quotas]
135141

142+
[discrete]
136143
[role="_additional-resources"]
137144
[id="additional-resources_aws-prerequisites_{context}"]
138145
== Additional resources

0 commit comments

Comments
 (0)