add loadBalancerSourceRanges as a preserved field#506
add loadBalancerSourceRanges as a preserved field#506matt-simons wants to merge 1 commit intoopenshift:masterfrom matt-simons:master
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: matt-simons The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @matt-simons. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
@matt-simons: PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
Issues go stale after 90d of inactivity. Mark the issue as fresh by commenting If this issue is safe to close now please do so with /lifecycle stale |
|
#507 reverted the change that caused the operator to set |
|
@Miciah: Closed this PR. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Case 02819675
As an OCP customer
I want to be able to set loadBalancerSourceRanges in the ingress service
so that I can restrict internet ingress to trusted sources
After upgrading from 4.5.x to 4.6.x we found that
loadBalancerSourceRangesis no longer preserved when we patch ourrouter-defaultService. This regression is blocking our ability to upgrade to 4.6 in production as we can not restrict internet access to our cluster ingress to trusted sources.This was a previously recommended solution https://access.redhat.com/solutions/5158751
It seems during the refactor release-4.5...openshift:release-4.6 only
ClusterIP,ExternalIPsandHealthCheckNodePortwere considered as fields that other controllers or users could modify. This PR would addLoadBalancerSourceRangesto that list for the existing use case above.Would it be possible to accept this PR and backport it to 4.6?