pivotal-cf / terraforming-azure

use terraform, deploy yourself a pcf
Apache License 2.0
34 stars 67 forks source link

network security group for `cf ssh` for small footprint PAS. #45

Open johnlafata opened 5 years ago

johnlafata commented 5 years ago

On Small footprint, we needed to update the network security group, pas-ops-manager-security-group, open port 2222. For Full PAS, Terraform takes care of this within the bosh-deployed-vms network security group.

dr8tsh commented 5 years ago

Hi @johnlafata - any reason you needed TCP2222 open against Ops Manager (the pas-ops-manager-security-group only applies against the OpsManager VM)? The NSG created as part of this Terraform (bosh-deployed-vms-security-group) includes a rule to allow TCP2222, which will allow cf ssh across both Small Footprint and standard PAS deployments.

To enable cf ssh in small footprint you will need to:

Will work with no changes required to the Terraform or security group.

koundinyabs commented 5 years ago

Hi @drhpivotal,

In John's deployment, for some reason the Ops manager NSG was assigned to the control VM. We concluded this was by design. Perhaps the root cause was not specifying the bosh-deployed-vms NSG as the default security group. John's deployment should still be around too check and confirm.