Bug 1873079
| Summary: | SSH to api and console route is possible when the clsuter is hosted on Openstack | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Arnab Ghosh <arghosh> |
| Component: | Installer | Assignee: | Emilien Macchi <emacchi> |
| Installer sub component: | OpenShift on OpenStack | QA Contact: | Udi Shkalim <ushkalim> |
| Status: | CLOSED ERRATA | Docs Contact: | |
| Severity: | medium | ||
| Priority: | medium | CC: | adduarte, asegurap, bbennett, eduen, emacchi, erich, juriarte, pprinett, rpalathi |
| Version: | 4.8 | Keywords: | Triaged |
| Target Milestone: | --- | ||
| Target Release: | 4.8.0 | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-07-27 22:32:47 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Arnab Ghosh
2020-08-27 10:26:55 UTC
I know it SSH access to the API-int and ingress is not really possible on cloud platforms, since usually that's the address of a cloud LB. Could you give me more info on what poses the security risk in being able to SSH to master or worker nodes from another IP address than the node one? Verified on: (shiftstack) [stack@undercloud-0 ~]$ oc get clusterversion NAME VERSION AVAILABLE PROGRESSING SINCE STATUS version 4.8.0-0.nightly-2021-04-17-044339 True False 3d1h Cluster version is 4.8.0-0.nightly-2021-04-17-044339 RHOSP 16.1 (shiftstack) [stack@undercloud-0 ~]$ ping api.ostest.shiftstack.com PING api.ostest.shiftstack.com (10.0.0.155) 56(84) bytes of data. 64 bytes from api.ostest.shiftstack.com (10.0.0.155): icmp_seq=1 ttl=63 time=1.91 ms (shiftstack) [stack@undercloud-0 ~]$ ssh core.shiftstack.com ssh: connect to host api.ostest.shiftstack.com port 22: Connection timed out Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Moderate: OpenShift Container Platform 4.8.2 bug fix and security update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2021:2438 |