F5Networks / f5-google-gdm-templates

Google Deployment Templates for quickly deploying BIG-IP services in Google Cloud Platform
28 stars 45 forks source link

Image not compatible with GCP Identity-Aware Proxy - Would be a great improvement #75

Closed cantepien closed 1 year ago

cantepien commented 2 years ago

Do you already have an issue opened with F5 support?

No

Description

It seems impossible to connect through GCP Identity-Aware Proxy. This would be a great feature to help securize F5 VE access in GCP.

Template

For bugs, enter the template with which you are experiencing issues below.

Severity Level

For bugs, enter the bug severity level. Do not set any labels.

Severity: <Fill in level: 1 through 5>

Severity level definitions:

  1. Severity 1 (Critical) : Defect is causing systems to be offline and/or nonfunctional. immediate attention is required.
  2. Severity 2 (High) : Defect is causing major obstruction of system operations.
  3. Severity 3 (Medium) : Defect is causing intermittent errors in system operations.
  4. Severity 4 (Low) : Defect is causing infrequent interuptions in system operations.
  5. Severity 5 (Trival) : Defect is not causing any interuptions to system operations, but none-the-less is a bug.
shyawnkarim commented 2 years ago

Thanks for submitting your issue. We are now tracking your enhancement request internally with ID, ESECLDTPLT-2875.

cantepien commented 2 years ago

Issue concerns 3nics. There is a conflict while both nic0 are necessary for GCP IAP and GCP load balancer. For 1nic, it works fine adding an admin key at project metadata level (I generated the key using: ssh-keygen -o -C "admin" -t rsa -m PEM)

cantepien commented 2 years ago

Also I forgot to mention that iap access works only if you set enable-oslogin to false in compute metadata

shyawnkarim commented 1 year ago

Closing due to age. These legacy templates are now in maintenance mode and are being replaced by our next-generation templates available in the Cloud Templates 2.0 GitHub repo.