BCDevOps / OpenShift4-Migration

Scripts and info for Ministry teams migration from OpenShift 3.11 to 4.x
Apache License 2.0
3 stars 0 forks source link

New default egress rules #38

Closed garywong-bc closed 2 years ago

garywong-bc commented 3 years ago

OCP4 is in the SDN Compartment, and uses Secure Internet Service Firewall that does do some filtering and IPS. For example, tcp/9700:9799 no longer works (by default).

Example spec:

spec:
  description: allow my namespace namespace to talk to the internet.
  destination:
    - - 'ext:network=any'
  source:
    - - $namespace=<mynamespace>-dev

RocketChat Reference(s):

For further details: If this egress is required, you may submit a firewall request with the source MCS-SILVER-NAT and just mention Secure Internet Service Firewall to: