Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1734136

Summary: RHCOS AMIs for AWS ap-east-1
Product: OpenShift Container Platform Reporter: W. Trevor King <wking>
Component: RHCOSAssignee: Steve Milner <smilner>
Status: CLOSED WONTFIX QA Contact: Micah Abbott <miabbott>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 4.1.zCC: bbreard, crawford, dustymabe, imcleod, jligon, nstielau, walters
Target Milestone: ---   
Target Release: 4.1.z   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-07-30 18:10:27 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description W. Trevor King 2019-07-29 17:39:16 UTC
The Hong Kong region is new 2019-04-25 [1].  If we upload RHCOS AMIs for that region, users will be able to run OpenShift there without having to copy the AMI over themselves or jumping through AMI-override hoops.

A useful side-effect of ap-east-1 support is that the installer's master branch landed the ap-east-1-referencing [2] before the ap-northeast-2-referencing [3].  We now want to backport [3] for bug 1725524, but the backport won't apply cleanly without [2,4].  If we decide we want ap-east-1 in 4.1.z, we will have grounds for landing [4].  Otherwise we'd have to manually backport the ap-northeast-2-referencing [3], which is not a big deal, but is unnecessary work if we are going to decide later that we do want ap-east-1 support in 4.1.z.
    
[1]: https://aws.amazon.com/blogs/aws/now-open-aws-asia-pacific-hong-kong-region/
[2]: https://github.com/openshift/installer/pull/1755
[3]: https://github.com/openshift/installer/pull/1935
[4]: https://github.com/openshift/installer/pull/2108

Comment 1 Colin Walters 2019-07-29 18:29:12 UTC
I think we should change the installer to support pulling the raw VMDK and upload that, and treat having it uploaded to the region as an optimization - yes, more cross-region traffic, but we need to pull a lot of data for the container images anyways, etc.   Ideally we can make it once-per-customer and not once-per-cluster.

Comment 2 W. Trevor King 2019-07-29 18:42:01 UTC
The installer already does copy-and-encrypt for the bootstrap and control-plane boot images.  It's easy to make that copy-and-encrypt cross-region (e.g. copying the us-east-1 AMI into an encrypted ap-east-1 AMI), see discussion under [1].  Probably easy enough to replace the copy-and-encrypt with a VMDK upload too.  The difficulty with all of that is cluster-API support, as linked from [2,3].  While we want to address that at some point, my guess is that it's going to be out-of-scope for 4.1.z.  Do we want to publish RHCOS AMIs to these additional regions (see also [4] mentioning cn-north-1 and cn-northwest-1) for 4.1.z support?  Or are we going to close-wontfix these additional regions for 4.1.z and then address the current cluster-API limitation in 4.2?  Or something else?

[1]: https://github.com/openshift/installer/pull/1296#discussion_r260310604
[2]: https://github.com/openshift/installer/issues/1354#issuecomment-469114604
[3]: https://github.com/openshift/os/issues/371#issuecomment-474079254
[4]: https://github.com/openshift/installer/issues/1354#issuecomment-469114604

Comment 4 Alex Crawford 2019-07-30 18:10:27 UTC
As per the documentation [1], OpenShift 4 doesn't support the ap-east-1 region. I'd rather us focus on getting the boot images managed instead of updating our RHCOS publishing pipeline.

[1]: https://docs.openshift.com/container-platform/4.1/installing/installing_aws/installing-aws-account.html#installation-aws-regions_installing-aws-account