検索

2.4. Configuring your firewall

download PDF

If you use a firewall, you must configure it so that OpenShift Container Platform can access the sites that it requires to function. You must always grant access to some sites, and you grant access to more if you use Red Hat Insights, the Telemetry service, a cloud to host your cluster, and certain build strategies.

2.4.1. Configuring your firewall for OpenShift Container Platform

Before you install OpenShift Container Platform, you must configure your firewall to grant access to the sites that OpenShift Container Platform requires.

Procedure

  1. Whitelist the following registry URLs:

    URLFunction

    registry.redhat.io

    Provides core container images

    *.quay.io

    Provides core container images

    sso.redhat.com

    The https://cloud.redhat.com/openshift site uses authentication from sso.redhat.com

  2. Whitelist any site that provides resources for a language or framework that your builds require.
  3. If you do not disable Telemetry, you must grant access to the following URLs to access Red Hat Insights:

    URLFunction

    cert-api.access.redhat.com

    Required for Telemetry

    api.access.redhat.com

    Required for Telemetry

    infogw.api.openshift.com

    Required for Telemetry

    https://cloud.redhat.com/api/ingress

    Required for Telemetry and for insights-operator

  4. If you use Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP) to host your cluster, you must grant access to the URLs that provide the cloud provider API and DNS for that cloud:

    CloudURLFunction

    AWS

    *.amazonaws.com

    Required to access AWS services and resources. Review the AWS Service Endpoints in the AWS documentation to determine the exact endpoints to allow for the regions that you use.

    GCP

    *.googleapis.com

    Required to access GCP services and resources. Review Cloud Endpoints in the GCP documentation to determine the endpoints to allow for your APIs.

    accounts.google.com

    Required to access your GCP account.

    Azure

    management.azure.com

    Required to access Azure services and resources. Review the Azure REST API Reference in the Azure documentation to determine the endpoints to allow for your APIs.

  5. Whitelist the following URLs:

    URLFunction

    mirror.openshift.com

    Required to access mirrored installation content and images

    *.apps.<cluster_name>.<base_domain>

    Required to access the default cluster routes unless you set an ingress wildcard during installation

    quay-registry.s3.amazonaws.com

    Required to access Quay image content in AWS

    api.openshift.com

    Required to check if updates are available for the cluster

    art-rhcos-ci.s3.amazonaws.com

    Required to download Red Hat Enterprise Linux CoreOS (RHCOS) images

    api.openshift.com

    Required for your cluster token

    cloud.redhat.com/openshift

    Required for your cluster token

Red Hat logoGithubRedditYoutubeTwitter

詳細情報

試用、購入および販売

コミュニティー

Red Hat ドキュメントについて

Red Hat をお使いのお客様が、信頼できるコンテンツが含まれている製品やサービスを活用することで、イノベーションを行い、目標を達成できるようにします。

多様性を受け入れるオープンソースの強化

Red Hat では、コード、ドキュメント、Web プロパティーにおける配慮に欠ける用語の置き換えに取り組んでいます。このような変更は、段階的に実施される予定です。詳細情報: Red Hat ブログ.

会社概要

Red Hat は、企業がコアとなるデータセンターからネットワークエッジに至るまで、各種プラットフォームや環境全体で作業を簡素化できるように、強化されたソリューションを提供しています。

© 2024 Red Hat, Inc.