[OSDOCS-11353] Document the whitelist IPs required for the ingress access to the API server#79139
Conversation
|
🤖 Fri Aug 02 20:03:24 - Prow CI generated the docs preview: https://79139--ocpdocs-pr.netlify.app/openshift-dedicated/latest/osd_planning/gcp-ccs.html |
|
|
||
| toc::[] | ||
|
|
||
| {product-title} users can use an OCM CLI command to obtain the most up-to-date whitelisted IP addresses that are necessary for SRE access to {product-title} clusters. |
There was a problem hiding this comment.
🤖 [error] RedHat.CaseSensitiveTerms: Use 'Red Hat OpenShift Cluster Manager' rather than 'OCM'. For more information, see RedHat.CaseSensitiveTerms.
| ==== | ||
| .Prerequisites | ||
| * You have a Google Cloud account with the proper permissions for access purposes. | ||
| * You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)]. |
There was a problem hiding this comment.
🤖 [error] RedHat.CaseSensitiveTerms: Use 'Red Hat OpenShift Cluster Manager' rather than 'the OpenShift Cluster Manager'. For more information, see RedHat.CaseSensitiveTerms.
| ==== | ||
| .Prerequisites | ||
| * You have a Google Cloud account with the proper permissions for access purposes. | ||
| * You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)]. |
There was a problem hiding this comment.
🤖 [error] OpenShiftAsciiDoc.SuggestAttribute: Use the AsciiDoc attribute '{cluster-manager}' rather than the plain text product term 'OpenShift Cluster Manager', unless your use case is an exception.
4c381ab to
f174b39
Compare
| These white-listed IP addresses are not permanent and are subject to change. You must continuously review the API output for the most current white-listed IP addresses. | ||
| ==== | ||
| .Prerequisites | ||
| * You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)]. |
There was a problem hiding this comment.
🤖 [error] RedHat.CaseSensitiveTerms: Use 'Red Hat OpenShift Cluster Manager' rather than 'the OpenShift Cluster Manager'. For more information, see RedHat.CaseSensitiveTerms.
| These white-listed IP addresses are not permanent and are subject to change. You must continuously review the API output for the most current white-listed IP addresses. | ||
| ==== | ||
| .Prerequisites | ||
| * You installed the link:https://console.redhat.com/openshift/downloads[OpenShift Cluster Manager API command-line interface (`ocm`)]. |
There was a problem hiding this comment.
🤖 [error] OpenShiftAsciiDoc.SuggestAttribute: Use the AsciiDoc attribute '{cluster-manager}' rather than the plain text product term 'OpenShift Cluster Manager', unless your use case is an exception.
|
from a technical point-of-view, it looks good to me. i mentioned to @mletalie that we aren't consistent with "whitelist" vs. "allowlist", but that's my only nit. |
|
Hello @xueli181114, May I get a review for this PR when you get a moment? Thanks! |
|
/lgtm |
|
/label peer-review-needed |
| + | ||
| [NOTE] | ||
| ==== | ||
| For information regarding allowlist IP addresses, see Additional resources. |
There was a problem hiding this comment.
Rewrite as: "For information about allowlist..."
| [id='required-whitelisted-overview'] | ||
| == Overview | ||
|
|
||
| In order for Red Hat SREs to troubleshoot any issues within {product-title} clusters, they must have ingress access to the API server through allowlist IP addresses. |
There was a problem hiding this comment.
Rewrite as: "For Red Hat SREs to troubleshoot any issues within..."
|
New changes are detected. LGTM label has been removed. |
|
/label merge-review-needed |
jldohmann
left a comment
There was a problem hiding this comment.
just a couple things before merge
|
|
||
| toc::[] | ||
|
|
||
| [id='required-whitelisted-overview'] |
There was a problem hiding this comment.
| [id='required-whitelisted-overview'] | |
| [id="required-whitelisted-overview_{context}"] |
|
|
||
| For Red Hat SREs to troubleshoot any issues within {product-title} clusters, they must have ingress access to the API server through allowlist IP addresses. | ||
|
|
||
| [id='required-whitelisted-access'] |
There was a problem hiding this comment.
| [id='required-whitelisted-access'] | |
| [id="required-whitelisted-access_{context}"] |
|
feel free to ping me on slack to merge when it's ready 👍 |
|
@mletalie: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
All good, thanks! |
|
/cherrypick enterprise-4.17 |
|
/cherrypick enterprise-4.16 |
|
@jldohmann: new pull request created: #79990 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@jldohmann: new pull request created: #79991 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Version(s):
4.16+
Issue:
https://issues.redhat.com/browse/OSDOCS-11353
Link to docs preview:
https://79139--ocpdocs-pr.netlify.app/openshift-dedicated/latest/security/rh-required-whitelisted-ip-addresses-for-sre-access
https://79139--ocpdocs-pr.netlify.app/openshift-dedicated/latest/osd_planning/gcp-ccs.html#ccs-gcp-requirements-security_gcp-ccs
QE review:
Additional information: