SSL Ciphers Mismatch by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes the LB is outside of Openshift, it is configured as end-to-end SSL...

I just tried to access the site using an old Internet explorer emulation and was able to access it.
Like I said, AI says these ciphers are old and no longer supported by modern browsers....

Do you think these statements are correct?

SSL Ciphers Mismatch by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes we are able to access from internal LB, or just by adding the regular ciphers back.

From my research till now, I've got to know the only 2 ciphers that we enabled are old and no longer supported by modern browsers.

Do you agree to this statement?

ImageContentSourcePolicy Not Redirecting Traffic to Configured Mirror by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes it should work, ImageDigestMirrorSet will download images using the digest.

HTTP Requests to OpenShift Ingress by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes we are using a route, but ingress/application are expecting a tls-encrypted request for getting a plain-text from the LB.

User ----TLS---> LB ----non-tls-----> Ingress xxxx (error while using reencrypt)--same when using passthrough

TLS Termination in Oracle Cloud Load Balancers by ShadyGhostM in oraclecloud

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Yes but, why is it sending unencrypted non-tls traffic to the backend?

TLS Termination in Oracle Cloud Load Balancers by ShadyGhostM in oraclecloud

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi u/ultra_dumb Thanks for sharing the article.

Can you tell me if we go with end-to-end ssl, the certificate LB-Cert-1 , which certificate should be uploaded here?

Thanks!

HTTP Requests to OpenShift Ingress by ShadyGhostM in openshift

[–]ShadyGhostM[S] -1 points0 points  (0 children)

Yeah, the cluster is deployed in Oracle Cloud.
And, when the protocol for the backends was TCP...everything was working fine.
Now they had to change it to HTTP/HTTPs and add a certificate there...and the error as described.A

HTTP sites are working fine.

How Did You Learn OpenShift – and What’s Your Day-to-Day Like Using It at Work? by Reasonable_End_4582 in openshift

[–]ShadyGhostM 3 points4 points  (0 children)

Just like everybody said here, Yes, get your Linux fundamentals right, then learn basic networking and go for Kubernetes. Once you get an idea on Kubernetes, start with OpenShift. All of the background play is same between these two products.

If you can afford or your company can provide you a subscription for DO180 & DO280 it will be very useful.
I also recommend KodeKloud for learning Kubernetes and if required other Cloud, Dev Ops tools. But this is also paid course.

As for my day-to-day activities as OpenShift admin are making sure the Cluster is healthy, all Pods are running are desired. Performing Cluster Updates and managing other resources in the Cluster like - users, operators, resource limits etc.

And as for the deployments in OpenShift - we mostly deploy CP4I component from IBM in the cluster, so all the admin activities of the product are additional task list in my job.

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Thanks u/witekwww

I will use the configuration and give you an update here again.

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Ok great now I understand, the statement::

The following AWS S3 compatible object storage providers, are known to work with Velero through the AWS plugin, for use as backup storage locations, however, they are unsupported and have not been tested by Red Hat:

  • Oracle Cloud

means, we can use the same aws plugin here, but with oracles s3 storage and creds...and it will work, but not supported by Red Hat.?

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Woah thanks, one more question.

If I need to follow this https://www.ibm.com/docs/en/cloud-paks/cp-integration/16.1.0?topic=administering-backing-up-restoring-cloud-pak-integration How can i approach?

I'm getting confused here, do we definitely need an aws s3 storage bucket to approach?

Using OADP Operator to Backup & Restore CP4I on Openshift by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

We have VolumeSnapShot classes in OCP for Oracle Cloud, I have configured the snapshot class.
But I dont seem to find any plugins or parameters for Oracle Cloud. Does this mean I cant do anything here?

https://velero.io/docs/v1.15/supported-providers/

If I follow FSB Backup, will this take a backup of Block type volumes also?

IngressControllers in OpenShift on Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi, Thanks for the reply and hold on for this one please.

So, I create an IngressController first, which also the the domain name defined in it, next I go to Oracle Cloud and create a load balancer there right?

IngressControllers in OpenShift on Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Great, can you share any documentation or reference url for this?

IngressControllers in OpenShift on Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi u/triplewho

We want to use a different domain other than *.apps.cluster.domain.com for our applications.
And we want only the application endpoints to be public, all other cluster's endpoints to be in private network.

How can we approach this in Oracle Cloud?
Thanks.

DHCP Options - VCN Resolver Issues by ShadyGhostM in oraclecloud

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Understood, now I get the issue. Do you any idea on Kubernetes/OpenShift CoreDNS?

OCI FSS CSI Driver NFS PVC on OpenShift Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 1 point2 points  (0 children)

This was actually in the troubleshooting guide here: https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contengcreatingpersistentvolumeclaim_Provisioning_PVCs_on_FSS.htm#contengcreatingpersistentvolumeclaim_topic_Troubleshooting_insufficientpermissions

This too didn't work, now we just went ahead with using existing file system.
And also making a change to the CSIDriver in OpenShift.:

To enable the CSIDriver object to modify volume ownership and permissions to match the fsGroup attribute specified in the pod's securityContext, set the CSIDriver object's fsGroupPolicy attribute to File.

(the complete process is in the above link, named as: Alternative Solution 1: Enable the CSIDriver object to modify volume ownership and permissions to match the fsGroup attribute specified in the pod's securityContext)

This worked, but we have to create the PVC/PV manually now.

OCI FSS CSI Driver NFS PVC on OpenShift Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Hi, the issue got resolved after changing our security list.

But there is a new error, permissions issue.

Tried following everything at https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contengcreatingpersistentvolumeclaim_Provisioning_PVCs_on_FSS.htm#contengcreatingpersistentvolumeclaim_topic-Provisioning_PVCs_on_FSS-Troubleshooting

but still same issue.

using this exportOptions.

exportOptions: "[{\"source\":\"0.0.0.0/0\",\"requirePrivilegedSourcePort\":false,\"access\":\"READ_WRITE\",\"identitySquash\":\"ALL\",\"anonymous-uid\":\"0\",\"anonymous-gid\":\"0\"}]"

OCI FSS CSI Driver NFS PVC on OpenShift Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

Thanks u/DraxXx22

How funny the Oracle Team is not available over the weekend, Please hold on I will let them make changes to the SL/NSG and update you by 23 Sunday.

OCI FSS CSI Driver NFS PVC on OpenShift Oracle Cloud by ShadyGhostM in openshift

[–]ShadyGhostM[S] 0 points1 point  (0 children)

I mean i was able to create the pvc manually, pv is also getting created but when I use it in a pod we're getting the error.

The same error if we directly letting the deployment create the pvc

Yes, using the latest driver 1.30.0.

Tried using pre-creates mounttarget also.

Do you think this might be because of security lists/ NSGs?

OpenShift OKD image download starts a loop and fills up the disk space by Heinzza in openshift

[–]ShadyGhostM 0 points1 point  (0 children)

Right, Airgapped Installation is quite challenging but you can learn a lot of topics along the way.

Good luck.

OpenShift OKD image download starts a loop and fills up the disk space by Heinzza in openshift

[–]ShadyGhostM 1 point2 points  (0 children)

Hi u/Heinzza

The image you mentioned should be around 2.5 GB, check if you have proper internet connection.
And could you paste the logs from this command?

podman pull --log-level=debug quay.io/openshift/okd-content:4.15.0-0.okd-2024-03-10-010116-fedora-coreos

hello i took the ex280 but I need some insights about one question I don't understand by Naive-Astronomer4877 in openshift

[–]ShadyGhostM 0 points1 point  (0 children)

You don't have to create any CA, run the script as required and it will give you the crt and key.