With OCP 4.7 IPSec for east-west traffic is a day-1 configuraiton. With OCP 4.8 this can also be applied as a day-2 configuration.
- Setup
install-config.yamlto use IPSec
networking:
networkType: OVNKubernetes| #!/bin/bash | |
| source ~/set-environment | |
| ADDING_NODES=${1:-"add-nodes"} | |
| USE_RENDERED=${2:-"true"} | |
| # path to rhcos-live iso | |
| export RHCOS_LIVE=~/images/rhcos-live.x86_64.iso | |
| if [ ! -f rhcos-live.x86_64.iso ]; then |
| #!/bin/bash | |
| set -euoE pipefail | |
| # Redfish commands related to Virtual Media. | |
| # Redfish doc reference: https://www.supermicro.com/manuals/other/RedfishRefGuide.pdf | |
| export BMC_ADDRESS='' | |
| export ISO_IMAGE=http://192.168.117.9:8080/ocp4-rwn-1-small.iso | |
| export username_password='Administrator:superuser' |
| --- | |
| apiVersion: sriovnetwork.openshift.io/v1 | |
| kind: SriovNetworkNodePolicy | |
| metadata: | |
| name: mh-vfio-ens2f0 | |
| namespace: openshift-sriov-network-operator | |
| spec: | |
| # name of Midhaul it connects to | |
| resourceName: mh_vfio_ens2f0 | |
| nodeSelector: |
| apiVersion: machineconfiguration.openshift.io/v1 | |
| kind: MachineConfig | |
| metadata: | |
| name: 50-worker-fix-keepalived | |
| labels: | |
| machineconfiguration.openshift.io/role: worker | |
| spec: | |
| config: | |
| ignition: | |
| version: 3.2.0 |
| --- | |
| apiVersion: machineconfiguration.openshift.io/v1 | |
| kind: MachineConfigPool | |
| metadata: | |
| name: ran-cu | |
| labels: | |
| machineconfiguration.openshift.io/role: ran-cu | |
| spec: | |
| machineConfigSelector: | |
| matchExpressions: |
| --- | |
| # oc edit ptpoperatorconfigs.ptp.openshift.io/default -n openshift-ptp | |
| # spec: | |
| # daemonNodeSelector: | |
| # node-role.kubernetes.io/worker-du: "" | |
| apiVersion: ptp.openshift.io/v1 | |
| kind: PtpConfig | |
| metadata: | |
| name: slave | |
| namespace: openshift-ptp |
| apiVersion: v1 | |
| kind: Pod | |
| metadata: | |
| name: simple-pod | |
| spec: | |
| #nodeSelector: | |
| # kubernetes.io/hostname: worker-1 | |
| containers: | |
| - name: simple-pod | |
| image: registry.access.redhat.com/ubi8/ubi |