Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Network architecture for CAPA/CAPV hybrid MC #3587

Closed
5 tasks done
Tracked by #3585
anvddriesch opened this issue Jul 23, 2024 · 3 comments
Closed
5 tasks done
Tracked by #3585

Network architecture for CAPA/CAPV hybrid MC #3587

anvddriesch opened this issue Jul 23, 2024 · 3 comments
Assignees
Labels
team/rocket Team Rocket

Comments

@anvddriesch
Copy link

anvddriesch commented Jul 23, 2024

some resources:
https://rutgerblom.com/2020/01/07/site-to-site-vpn-between-nsx-t-tier-1-and-aws-vpc/
https://intranet.giantswarm.io/docs/product/providers/capz/multi-provider/

Our MC is on CAPA. It is capable of provisioning CAPV and CAPA workload clusters.|
CAPA MC is private with proxy
CAPA MC is able to access the vSphere API.
CAPA MC is able to access all CAPV WCs.
CAPV WCs are able to access endpoints (k8s API and ingresses) of the MC.

Tasks

@anvddriesch
Copy link
Author

We set up the VPNs on IONOS and AWS sides modeled based on our Azure environment.
Thanks to Simon and Xavier we finally got it working and Vsphere nodes are now reachable from goat mc nodes.

@anvddriesch
Copy link
Author

CAPA MC is private with proxy ✅
CAPA MC is able to access all CAPV WCs. ✅
CAPV WCs are able to access endpoints (k8s API and ingresses) of the MC. ✅
CAPA MC is able to access the vSphere API. ⛔

For some odd reason we can not make the connection from AWS through GS VPN to the vcenter work. We tried on a different installation and had the same problem so it does not seem to be specific to the private environment but related to aws.

@glitchcrab
Copy link
Member

i don't want to lose this - we need to add vcenter-rhr3c72bx1.ionoscloud.tools to goat's NO_PROXY vars

@anvddriesch anvddriesch added team/rocket Team Rocket and removed team/bigmac Team BigMac labels Aug 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
team/rocket Team Rocket
Projects
Archived in project
Development

No branches or pull requests

3 participants