Skip to content

[OSDOCS-11353] Document the whitelist IPs required for the ingress access to the API server#79139

Merged
jldohmann merged 1 commit intoopenshift:mainfrom
mletalie:OSDOCS-11353
Aug 5, 2024
Merged

[OSDOCS-11353] Document the whitelist IPs required for the ingress access to the API server#79139
jldohmann merged 1 commit intoopenshift:mainfrom
mletalie:OSDOCS-11353

Conversation

@mletalie
Copy link
Contributor

@mletalie mletalie commented Jul 19, 2024

@openshift-ci openshift-ci bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 19, 2024
@mletalie mletalie changed the title IP Whitelist for OSD [OSDOCS-11353] Document the whitelist IPs required for the ingress access to the API server Jul 19, 2024
@ocpdocs-previewbot
Copy link

ocpdocs-previewbot commented Jul 19, 2024

@openshift-ci openshift-ci bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 22, 2024

toc::[]

{product-title} users can use an OCM CLI command to obtain the most up-to-date whitelisted IP addresses that are necessary for SRE access to {product-title} clusters.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 [error] RedHat.CaseSensitiveTerms: Use 'Red Hat OpenShift Cluster Manager' rather than 'OCM'. For more information, see RedHat.CaseSensitiveTerms.

@openshift-ci openshift-ci bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 25, 2024
====
.Prerequisites
* You have a Google Cloud account with the proper permissions for access purposes.
* You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)].
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 [error] RedHat.CaseSensitiveTerms: Use 'Red Hat OpenShift Cluster Manager' rather than 'the OpenShift Cluster Manager'. For more information, see RedHat.CaseSensitiveTerms.

====
.Prerequisites
* You have a Google Cloud account with the proper permissions for access purposes.
* You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)].
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 [error] OpenShiftAsciiDoc.SuggestAttribute: Use the AsciiDoc attribute '{cluster-manager}' rather than the plain text product term 'OpenShift Cluster Manager', unless your use case is an exception.

@mletalie mletalie force-pushed the OSDOCS-11353 branch 4 times, most recently from 4c381ab to f174b39 Compare July 31, 2024 15:07
These white-listed IP addresses are not permanent and are subject to change. You must continuously review the API output for the most current white-listed IP addresses.
====
.Prerequisites
* You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)].
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 [error] RedHat.CaseSensitiveTerms: Use 'Red Hat OpenShift Cluster Manager' rather than 'the OpenShift Cluster Manager'. For more information, see RedHat.CaseSensitiveTerms.

These white-listed IP addresses are not permanent and are subject to change. You must continuously review the API output for the most current white-listed IP addresses.
====
.Prerequisites
* You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)].
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 [error] OpenShiftAsciiDoc.SuggestAttribute: Use the AsciiDoc attribute '{cluster-manager}' rather than the plain text product term 'OpenShift Cluster Manager', unless your use case is an exception.

@jaybeeunix
Copy link
Member

from a technical point-of-view, it looks good to me. i mentioned to @mletalie that we aren't consistent with "whitelist" vs. "allowlist", but that's my only nit.

@mletalie
Copy link
Contributor Author

Hello @xueli181114, May I get a review for this PR when you get a moment? Thanks!

@yuwang-RH
Copy link
Member

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Aug 2, 2024
@mletalie
Copy link
Contributor Author

mletalie commented Aug 2, 2024

/label peer-review-needed

@openshift-ci openshift-ci bot added the peer-review-needed Signifies that the peer review team needs to review this PR label Aug 2, 2024
@lpettyjo lpettyjo added peer-review-in-progress Signifies that the peer review team is reviewing this PR and removed peer-review-needed Signifies that the peer review team needs to review this PR labels Aug 2, 2024
@lpettyjo lpettyjo self-requested a review August 2, 2024 15:33
@lpettyjo lpettyjo added this to the Continuous Release milestone Aug 2, 2024
Copy link
Contributor

@lpettyjo lpettyjo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Otherwise, LGTM!

+
[NOTE]
====
For information regarding allowlist IP addresses, see Additional resources.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rewrite as: "For information about allowlist..."

[id='required-whitelisted-overview']
== Overview

In order for Red Hat SREs to troubleshoot any issues within {product-title} clusters, they must have ingress access to the API server through allowlist IP addresses.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rewrite as: "For Red Hat SREs to troubleshoot any issues within..."

@lpettyjo lpettyjo added peer-review-done Signifies that the peer review team has reviewed this PR and removed peer-review-in-progress Signifies that the peer review team is reviewing this PR labels Aug 2, 2024
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Aug 2, 2024
@openshift-ci
Copy link

openshift-ci bot commented Aug 2, 2024

New changes are detected. LGTM label has been removed.

@mletalie
Copy link
Contributor Author

mletalie commented Aug 2, 2024

/label merge-review-needed

@openshift-ci openshift-ci bot added the merge-review-needed Signifies that the merge review team needs to review this PR label Aug 2, 2024
@jldohmann jldohmann added the merge-review-in-progress Signifies that the merge review team is reviewing this PR label Aug 2, 2024
Copy link
Contributor

@jldohmann jldohmann left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just a couple things before merge


toc::[]

[id='required-whitelisted-overview']
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
[id='required-whitelisted-overview']
[id="required-whitelisted-overview_{context}"]


For Red Hat SREs to troubleshoot any issues within {product-title} clusters, they must have ingress access to the API server through allowlist IP addresses.

[id='required-whitelisted-access']
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
[id='required-whitelisted-access']
[id="required-whitelisted-access_{context}"]

@jldohmann jldohmann removed merge-review-in-progress Signifies that the merge review team is reviewing this PR merge-review-needed Signifies that the merge review team needs to review this PR labels Aug 2, 2024
@jldohmann
Copy link
Contributor

feel free to ping me on slack to merge when it's ready 👍

@openshift-ci
Copy link

openshift-ci bot commented Aug 2, 2024

@mletalie: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@mletalie
Copy link
Contributor Author

mletalie commented Aug 2, 2024

feel free to ping me on slack to merge when it's ready 👍

All good, thanks!
Pinged you via Slack.

@jldohmann jldohmann merged commit 8744fe7 into openshift:main Aug 5, 2024
@jldohmann
Copy link
Contributor

/cherrypick enterprise-4.17

@jldohmann
Copy link
Contributor

/cherrypick enterprise-4.16

@openshift-cherrypick-robot

@jldohmann: new pull request created: #79990

Details

In response to this:

/cherrypick enterprise-4.17

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-cherrypick-robot

@jldohmann: new pull request created: #79991

Details

In response to this:

/cherrypick enterprise-4.16

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.16 branch/enterprise-4.17 peer-review-done Signifies that the peer review team has reviewed this PR size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants