vmware / cloud-provider-for-cloud-director

Kubernetes External Cloud Provider for VMware Cloud Director
Other
20 stars 30 forks source link

Annotate service to bypass EXTERNAL-IP on firewall #381

Open srekkas opened 1 month ago

srekkas commented 1 month ago

Is your feature request related to a problem? Please describe.

As we create service and get external ip, we expect to reach it. But we need to manually configure firewall after that.

Describe the solution you'd like

Annotate service with something like this

  annotations:
    service.beta.kubernetes.io/vcloud-avi-dnat-bypass-firewall: "true" 

or maybe even it can create dynamic firewall rule from ip list

  annotations:
    service.beta.kubernetes.io/vcloud-avi-dnat-firewall-iplist: "X.X.X.X, Y.Y.Y.Y"

Describe alternatives you've considered

No response

Additional context

No response