-
Notifications
You must be signed in to change notification settings - Fork 3.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added mesh ingress content to instances chapter. #14854
Conversation
@TheRealHaoLiu, @fosterseth - is this how we want to document this feature? I didn't get real screens, I purely based it on the demo you all did for me and used the screens from there so they are consistent. So if we stick with this, we will need to recapture these exact screens. |
Configuring a mesh ingress | ||
--------------------------- | ||
|
||
If a remote execution node is setup inside a datacenter to communicate with target hosts from a k8s cluster because the k8s cluster is unable to reach the hosts via SSH, it risks exposing port information. To solve this, a hop node is placed inside of the k8s cluster to route traffic from task pods to the execution node, eliminating the risk of exposing any ports since execution node connections are outbound only. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Creating a remote execution node without enabling mesh ingress you would have to allow inbound connection to the receptor listener port on the remote execution node
In restricted networking environment (inside private network) where this connection is not allowed using mesh ingress can allow the remote execution to connect into the awx control-plane instead of having to allow connection from the awx control-plane
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
To solve this, a hop node is placed inside of the k8s cluster to route traffic from task pods to the execution node
more of implementation detail... the ingress present as a hop node in the instance page to allow user to peer into the mesh
…h-ingress # Conflicts: # docs/docsite/rst/administration/instances.rst
SUMMARY
This PR outlines the process for setting up and configuring an example mesh ingress scenario.
It addresses issue #14816.
It has a dependency on (operator PR #1706) for links to work but they are correct when they get published.
See rendered preview: https://ansible--14854.org.readthedocs.build/projects/awx/en/14854/administration/instances.html
ISSUE TYPE
COMPONENT NAME
AWX VERSION
Latest
ADDITIONAL INFORMATION
Associated with AAP 2.5