Document URL: https://docs.openshift.com/container-platform/4.10/installing/installing_aws/installing-restricted-networks-aws.html#installation-requirements-user-infra_installing-restricted-networks-aws Section Number and Name: "Installing a cluster on AWS in a restricted network with user-provisioned infrastructure" Describe the issue: For disconnected clusters, OpenShift can be configured not to manage DNS, and the cluster administrator can configure DNS manually. Otherwise, the ingress operator will try to contact the STS endpoint "sts.amazon.com" directly as opposed to the configured VPC endpoint for the cluster. This could be an issue in cases when the cluster needs to be as air-gapped as possible. Suggestions for improvement: https://github.com/openshift/installer/pull/5974/files Additional information: