OSDOCS-6652 AWS shared private hosted zones#64114
Conversation
|
🤖 Updated build preview is available at: Build log: https://circleci.com/gh/ocpdocs-previewbot/openshift-docs/29320 |
5c93e89 to
118b999
Compare
118b999 to
3b79f66
Compare
|
@yunjiang29 PTAL at this PR modifying the AWS "existing VPC" documentation to account for the shared private hosted zone feature for AWS. Thank you |
|
@bscott-rh Some notable info for your reference: Restriction for Shared-VPC install:
For Cluster owner’s account (Account-B)
For VPC&PHZ owner's account (Account-A)
|
3b79f66 to
5b6fdd4
Compare
4c04694 to
01835d3
Compare
Thanks Yunfei, I have updated the PR to 1) Add the permissions information to the account page 2) add the extra information about the credentials modes and 3) add a new module to the account page describing the trust policy modifications. Please let me know if what I've written makes sense as I am not an AWS expert :) |
yunjiang29
left a comment
There was a problem hiding this comment.
@bscott-rh thank you for the updates, I added some comments, let me know if there is anything unclear.
| |String, for example `Z3URY6TWQ91KVV`. | ||
|
|
||
| |`platform.aws.hostedZoneRole` | ||
| |An Amazon Resource Name (ARN) for an existing IAM Role in the account containing the specified hosted zone. The installation program and cluster operators will assume this role when performing operations on the hosted zone. |
There was a problem hiding this comment.
-
The
platform.aws.hostedZoneRoleis designed for Shared VPC scenario, and in the account configuration section, we used wordshared VPC, I would suggest to mention shared VPC in this part, to correspond to the former. -
As my comment, I think we can move trust policy and permission content to here.
There was a problem hiding this comment.
Good point, I've made that addition.
01835d3 to
0905a65
Compare
|
LGTM except the one small comment |
0905a65 to
cd6cc1a
Compare
yunjiang29
left a comment
There was a problem hiding this comment.
@bscott-rh looks good to me, just need a small update.
cd6cc1a to
9ac19f7
Compare
jldohmann
left a comment
There was a problem hiding this comment.
Nice job Ben! generally LGTM, some ISG nits below
9ac19f7 to
9202f48
Compare
9202f48 to
4e0b3f1
Compare
|
/cherrypick enterprise-4.14 |
|
@bscott-rh: new pull request created: #66667 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Version(s):
4.14
Issue:
https://issues.redhat.com/browse/OSDOCS-6652
Link to docs preview:
https://64114--docspreview.netlify.app/openshift-enterprise/latest/installing/installing_aws/installing-aws-vpc#installation-custom-aws-vpc-requirements_installing-aws-vpc
QE review: