Skip to content

OSDOCS-16264#adding AWS EUSC#110585

Merged
ShaunaDiaz merged 1 commit intoopenshift:mainfrom
brendan-daly-red-hat:OSDOCS-16264
May 5, 2026
Merged

OSDOCS-16264#adding AWS EUSC#110585
ShaunaDiaz merged 1 commit intoopenshift:mainfrom
brendan-daly-red-hat:OSDOCS-16264

Conversation

@brendan-daly-red-hat
Copy link
Copy Markdown
Contributor

@brendan-daly-red-hat brendan-daly-red-hat commented Apr 22, 2026

Versions:
4.22+

Issue:
https://redhat.atlassian.net/browse/OSDOCS-16264

Link to docs preview:

QE review:

  • QE has approved this change.

Additional information:

@openshift-ci openshift-ci Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Apr 22, 2026
@brendan-daly-red-hat brendan-daly-red-hat changed the title Osdocs 16264 OSDOCS-16264#adding EUSC TP Apr 22, 2026
@ocpdocs-previewbot
Copy link
Copy Markdown

ocpdocs-previewbot commented Apr 22, 2026

Comment thread modules/installation-aws-eusc.adoc Outdated
@openshift-ci openshift-ci Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Apr 22, 2026
Comment thread modules/installation-aws-about-eusc.adoc Outdated
Comment thread modules/installation-aws-about-eusc.adoc Outdated
@brendan-daly-red-hat brendan-daly-red-hat changed the title OSDOCS-16264#adding EUSC TP OSDOCS-16264#adding AWS EUSC Apr 23, 2026
@openshift-ci openshift-ci Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Apr 23, 2026
@brendan-daly-red-hat brendan-daly-red-hat force-pushed the OSDOCS-16264 branch 10 times, most recently from 0f6c94e to 1d9b3c9 Compare April 28, 2026 15:30
Copy link
Copy Markdown
Contributor

@bscott-rh bscott-rh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work! I left two suggestions for combining into one section for simplicity.

Comment thread modules/installation-aws-regions.adoc Outdated
:FeatureName: European Sovereign Cloud (EUSC) region
include::snippets/technology-preview.adoc[leveloffset=+1]

Installing an {product-title} cluster into the {aws-short} EUSC region helps maximize the sovereignty of your data and satisfy your organization's regulatory requirements. The {aws-short} EUSC is separate and independent from other {aws-short} regions. The infrastructure is located wholly within the European Union (EU). For more information, see "Establishing a European trust service provider for the {aws-short} European Sovereign Cloud".
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would move this to the previous section, between lines 58 and 59.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied this change.

Comment thread modules/installation-aws-regions.adoc Outdated
Comment on lines +73 to +83
The following list outlines the limitations that apply to installing an {product-title} cluster into the {aws-short} EUSC region:

* Only one region, `eusc-de-east-1`, and two zones in that region are available.

* The Amazon Machine Images (AMIs) for public {op-system-first} are not yet available in the EUSC region. As a workaround, until the AMI publication for {op-system} is extended to the EUSC region, you must edit your `install-config.yaml` file to specify a custom AMI in the `amiID` field.

* The {aws-short} Security Token Service (STS) is not supported.

* Support is not yet provided for installing a cluster into a shared Virtual Private Cloud (VPC).

* Support is not yet provided for bringing your own encryption keys.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd move this into an [IMPORTANT] admonition in the previous section, perhaps after you list the Brandenburg region name.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied this change.

@brendan-daly-red-hat brendan-daly-red-hat force-pushed the OSDOCS-16264 branch 2 times, most recently from 67e6aa5 to f7311ff Compare April 29, 2026 10:00
@brendan-daly-red-hat
Copy link
Copy Markdown
Contributor Author

@tthvo, @patrickdillon, PTAL

Comment thread modules/installation-aws-regions.adoc Outdated
* `us-west-1` (N. California)
* `us-west-2` (Oregon)

[id="installation-aws-eusc_region{context}"]
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
[id="installation-aws-eusc_region{context}"]
[id="installation-aws-eusc_region_{context}"]

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied this change.

* xref:../../installing/installing_aws/ipi/installing-aws-default.adoc#installing-aws-default[Quickly install a cluster]
* xref:../../installing/installing_aws/ipi/installing-aws-customizations.adoc#installing-aws-customizations[Install a cluster with cloud customizations on installer-provisioned infrastructure]
* xref:../../installing/installing_aws/upi/installing-aws-user-infra.adoc#installing-aws-user-infra[Installing a cluster on user-provisioned infrastructure in AWS by using CloudFormation templates]
* link:https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html[Establishing a European trust service provider for the {aws-short} European Sovereign Cloud ({aws-short} documentation)]
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Contributor Author

@brendan-daly-red-hat brendan-daly-red-hat Apr 30, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed this entry and added the correct link as a hyperlink in the module text.

Comment thread modules/installation-aws-regions.adoc Outdated
:FeatureName: European Sovereign Cloud (EUSC) region
include::snippets/technology-preview.adoc[leveloffset=+1]

Installing an {product-title} cluster into the {aws-short} European Sovereign Cloud (EUSC) region helps maximize the sovereignty of your data and satisfy your organization's regulatory requirements. The {aws-short} EUSC is separate and independent from other {aws-short} regions. The infrastructure is located wholly within the European Union (EU). For more information, see "Establishing a European trust service provider for the {aws-short} European Sovereign Cloud".
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The section "Establishing a European trust service provider for the {aws-short} European Sovereign Cloud" is supposed to be a hyperlink, right? It seems to be plain text to me (i.e. no link to aws annoucement)...

Comment thread modules/installation-aws-regions.adoc Outdated

* The {aws-short} Security Token Service (STS) is not supported.

* Support is not yet provided for installing a cluster into a shared Virtual Private Cloud (VPC).
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Support is not yet provided for installing a cluster into a shared Virtual Private Cloud (VPC).
* Installing a cluster into a shared Virtual Private Cloud (VPC) with a cross-account private hosted zone is not yet supported.

Installing into a shared or existing VPC is indeed supported. However, if the user chooses to utilize a private hosted zone from another account (see EP and openshift doc), this is not supported.

Sorry, if I was not clear before 😅

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied this change.

Comment thread modules/installation-aws-regions.adoc Outdated

* The Amazon Machine Images (AMIs) for public {op-system-first} are not yet available in the EUSC region. As a workaround, until the AMI publication for {op-system} is extended to the EUSC region, you must edit your `install-config.yaml` file to specify a custom AMI in the `amiID` field.

* The {aws-short} Security Token Service (STS) is not supported.
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* The {aws-short} Security Token Service (STS) is not supported.
* The {aws-short} Security Token Service (STS) is not yet supported.

For consistency with other below entries.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied this change.

Comment thread modules/installation-aws-regions.adoc Outdated

* Support is not yet provided for installing a cluster into a shared Virtual Private Cloud (VPC).

* Support is not yet provided for bringing your own encryption keys.
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Support is not yet provided for bringing your own encryption keys.

Technically, it is supported. I have tested this scenario myself, but waiting on storage team to confirm storage testing.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cc @rhrmo

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tthvo as soon as I manage to get a cluster to start up I will test it and let you know, but it should work imo

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tthvo I did a quick test and it works

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good, thanks @rhrmo!

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Support is not yet provided for bringing your own encryption keys.

@brendan-daly-red-hat can we remove this line as it's confirmed to be supported?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied this change.

@brendan-daly-red-hat brendan-daly-red-hat force-pushed the OSDOCS-16264 branch 4 times, most recently from 46d196d to 2c6d2ca Compare April 30, 2026 14:42
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 30, 2026

@brendan-daly-red-hat: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Copy link
Copy Markdown
Member

@tthvo tthvo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Apr 30, 2026
@brendan-daly-red-hat
Copy link
Copy Markdown
Contributor Author

/label merge-review-needed

@openshift-ci openshift-ci Bot added the merge-review-needed Signifies that the merge review team needs to review this PR label May 5, 2026
Copy link
Copy Markdown
Contributor

@ShaunaDiaz ShaunaDiaz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm


[IMPORTANT]
====

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change

* Support is not yet provided for the {aws-short} Security Token Service (STS).

* Support is not yet provided for installing a cluster into a shared Virtual Private Cloud (VPC) with a cross-account private hosted zone.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change

not a merge blocker, but i have no idea if dita will trip on extraneous line spaces in admonitions; something to consider

@ShaunaDiaz ShaunaDiaz added branch/enterprise-4.22 and removed merge-review-needed Signifies that the merge review team needs to review this PR labels May 5, 2026
@ShaunaDiaz ShaunaDiaz added this to the Planned for 4.22 GA milestone May 5, 2026
@ShaunaDiaz ShaunaDiaz merged commit eb93e53 into openshift:main May 5, 2026
2 checks passed
@ShaunaDiaz
Copy link
Copy Markdown
Contributor

/cherrypick enterprise-4.22

@openshift-cherrypick-robot
Copy link
Copy Markdown

@ShaunaDiaz: new pull request created: #111231

Details

In response to this:

/cherrypick enterprise-4.22

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.22 lgtm Indicates that a PR is ready to be merged. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants