7.4. AWS PrivateLink 接続の有効化
プライベートリンク接続を有効にするには、カスタマーサポートチケットを作成してください。Red Hat チームが次の手順でサポートします。
注記
双方向接続を実現するには、2 つの 別々のサポートチケットを作成する必要があります。
- お客様 VPC からコントロールプレーン への AWS PrivateLink 接続を可能にするもの
- 1 つ目は、コントロールプレーン から お客様 VPC への AWS PrivateLink 接続を可能にすることです。
7.4.1. お客様の VPC から Red Hat が管理するコントロールプレーンへの AWS PrivateLink 接続を設定する リンクのコピーリンクがクリップボードにコピーされました!
リンクのコピーリンクがクリップボードにコピーされました!
この設定により、内部ユーザーと自動化は PrivateLink 経由で Ansible Automation Platform UI と API にアクセスできます。
手順
- Ingress PrivateLink をリクエストするには、手順 2 の Ingress AWS PrivateLink リクエストテンプレート を使用して、Red Hat に カスタマーサポート ケースを送信してください。
以下の情報を含める必要があります。
- AWS アカウント ID
- リージョン。
- デプロイメント URL。
- Red Hat から VPC エンドポイントサービス名を受け取ったら、その提供されたサービス名を指す VPC エンドポイントを AWS アカウントに作成する必要があります。
Ingress AWS PrivateLink リクエストテンプレート の場合:
NLB および GWLB を使用するエンドポイントサービスを選択してください。
- サービス名 フィールドに、Red Hat から提供された VPC エンドポイントサービス名を貼り付け、 をクリックします。
組織の要件に従って、ネットワークとセキュリティーグループの設定を完了してください。
Subject: Request for Ingress PrivateLink Connection: <Your Company Name> - <Deployment ID> Body: Hello Red Hat Support, We would like to enable Ingress PrivateLink connectivity for our AAP on AWS instance. This will allow our internal users and automation tools to access the AAP Control Plane (UI/API) securely from our VPC without traversing the public internet. Deployment details: AAP Deployment Name/ID: <for example., ans-123456> AAP Deployment URL: <for example, https://ans-123456.ansible.redhat.com> Our Network Information: Our AWS Account ID: <Your 12-digit AWS Account ID> Target Region: <for example, us-east-1> Action required: Please create the Endpoint Service configuration on the Control Plane side and provide us with the VPC Endpoint Service Name so we can create the interface endpoint in our VPC. Thank you.