Bug 1390459 - Redirect management console HTTP to HTTPS [NEEDINFO]
Summary: Redirect management console HTTP to HTTPS
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: RFE
Version: 3.2.0
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: ---
Assignee: Jessica Forrester
QA Contact: Xiaoli Tian
URL:
Whiteboard:
: 1317604 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-11-01 06:00 UTC by Jaspreet Kaur
Modified: 2020-03-11 15:20 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-02-03 15:41:45 UTC
Target Upstream Version:
sspeiche: needinfo? (ccoleman)


Attachments (Terms of Use)

Description Jaspreet Kaur 2016-11-01 06:00:29 UTC
3. What is the nature and description of the request?

Currently openshift console can only be accessed via https however when we access it using http we get a blank page. We want to have a redirection instead to https so that the end user is not effected by this.

4. Why does the customer need this? (List the business requirements here)

 We're standing up a replacement for the ITOS service.  To load balance the masters we're using AWS ELBs.  unlike the load balancers we use in the Data Center AWS ELBs are extremely minimal and don't allow us to perform redirects.  To improve the experience for our internal customers we'd like to ensure that the standard web console for the OpenShift instance redirects from HTTP to HTTPS.

The OpenShift masters are currently listing only on 8053, 443, 8444 and 10250 (with nothing listening on 80)


5. How would the customer like to achieve this? (List the functional requirements here)

Whenever the webconsole is accessed using http protocol we want this to be redirected to https.

Comment 3 Jessica Forrester 2016-11-14 20:02:31 UTC
*** Bug 1317604 has been marked as a duplicate of this bug. ***

Comment 5 Mark Chappell 2017-02-03 16:51:09 UTC
As the customer, I'm a little disappointed to see this closed:wontfix.

As mentioned in the RFE, it sucks but Amazon's Load Balancing solution (ELB) does not offer any kind of redirection functionality.  They're incredibly simplistic.  In the Data Center this is far less of an issue as we have load balancers making a simple HTTP->HTTPS redirect trivial.

By refusing this RFE you're forcing us to apply little extra things to account for one of the most common use cases going: users who can't be bothered to type https://www.example.com into their browser and simply type www.example.com

For anyone out there looking for an example work around: Red Hat IT has worked around this with a daemonset running on the master nodes (a privileged container which uses the hosts networking) which just serves a hard coded 302 redirect.  There's a number of example containers out there doing this.

Comment 6 Steve Speicher 2017-04-07 17:23:51 UTC
Pinging Clayton for additional input based on hallway discussion.


Note You need to log in before you can comment on or make changes to this bug.