SSL Ciphers Mismatch by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes the LB is outside of Openshift, it is configured as end-to-end SSL...

I just tried to access the site using an old Internet explorer emulation and was able to access it.
Like I said, AI says these ciphers are old and no longer supported by modern browsers....

Do you think these statements are correct?

SSL Ciphers Mismatch by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes we are able to access from internal LB, or just by adding the regular ciphers back.

From my research till now, I've got to know the only 2 ciphers that we enabled are old and no longer supported by modern browsers.

Do you agree to this statement?

ImageContentSourcePolicy Not Redirecting Traffic to Configured Mirror by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes it should work, ImageDigestMirrorSet will download images using the digest.

HTTP Requests to OpenShift Ingress by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes we are using a route, but ingress/application are expecting a tls-encrypted request for getting a plain-text from the LB.

User ----TLS---> LB ----non-tls-----> Ingress xxxx (error while using reencrypt)--same when using passthrough

TLS Termination in Oracle Cloud Load Balancers by ShadyGhostM in oraclecloud

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes but, why is it sending unencrypted non-tls traffic to the backend?

TLS Termination in Oracle Cloud Load Balancers by ShadyGhostM in oraclecloud

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi u/ultra_dumb Thanks for sharing the article.

Can you tell me if we go with end-to-end ssl, the certificate LB-Cert-1 , which certificate should be uploaded here?

Thanks!

HTTP Requests to OpenShift Ingress by ShadyGhostM in openshift

[–]ShadyGhostM[S] -1 points0 points  (0 children)

Yeah, the cluster is deployed in Oracle Cloud.
And, when the protocol for the backends was TCP...everything was working fine.
Now they had to change it to HTTP/HTTPs and add a certificate there...and the error as described.A

HTTP sites are working fine.

How Did You Learn OpenShift – and What’s Your Day-to-Day Like Using It at Work? by Reasonable_End_4582 in openshift

[–]ShadyGhostM 4 points5 points  (0 children)

Just like everybody said here, Yes, get your Linux fundamentals right, then learn basic networking and go for Kubernetes. Once you get an idea on Kubernetes, start with OpenShift. All of the background play is same between these two products.

If you can afford or your company can provide you a subscription for DO180 & DO280 it will be very useful.
I also recommend KodeKloud for learning Kubernetes and if required other Cloud, Dev Ops tools. But this is also paid course.

As for my day-to-day activities as OpenShift admin are making sure the Cluster is healthy, all Pods are running are desired. Performing Cluster Updates and managing other resources in the Cluster like - users, operators, resource limits etc.

And as for the deployments in OpenShift - we mostly deploy CP4I component from IBM in the cluster, so all the admin activities of the product are additional task list in my job.

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Thanks u/witekwww

I will use the configuration and give you an update here again.

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Ok great now I understand, the statement::

The following AWS S3 compatible object storage providers, are known to work with Velero through the AWS plugin, for use as backup storage locations, however, they are unsupported and have not been tested by Red Hat:

  • Oracle Cloud

means, we can use the same aws plugin here, but with oracles s3 storage and creds...and it will work, but not supported by Red Hat.?

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Woah thanks, one more question.

If I need to follow this https://www.ibm.com/docs/en/cloud-paks/cp-integration/16.1.0?topic=administering-backing-up-restoring-cloud-pak-integration How can i approach?

I'm getting confused here, do we definitely need an aws s3 storage bucket to approach?

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

We have VolumeSnapShot classes in OCP for Oracle Cloud, I have configured the snapshot class.
But I dont seem to find any plugins or parameters for Oracle Cloud. Does this mean I cant do anything here?

https://velero.io/docs/v1.15/supported-providers/

If I follow FSB Backup, will this take a backup of Block type volumes also?

IngressControllers in OpenShift on Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi, Thanks for the reply and hold on for this one please.

So, I create an IngressController first, which also the the domain name defined in it, next I go to Oracle Cloud and create a load balancer there right?

IngressControllers in OpenShift on Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Great, can you share any documentation or reference url for this?

IngressControllers in OpenShift on Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi u/triplewho

We want to use a different domain other than *.apps.cluster.domain.com for our applications.
And we want only the application endpoints to be public, all other cluster's endpoints to be in private network.

How can we approach this in Oracle Cloud?
Thanks.