Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Api proposal 2 #16

Closed
wants to merge 2 commits into from
Closed

Api proposal 2 #16

wants to merge 2 commits into from

Conversation

Fredi-raspall
Copy link

No description provided.

@Fredi-raspall Fredi-raspall self-assigned this Mar 4, 2025

## Constraints
* An external addresses can belong to only one VPC.
* No other restriction is needed IMO, but happy to discuss why.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you discuss why? Dealing with multiple pifs with the same IP addresses and return routes in the gateway was the whole issue here, especially if there are conflicting policies between the PIFs (e.g., firewall rules, PAT, etc.). Why is this no longer an issue?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, my example for the firewall rules at the pif level was not good.
The intent --still valid-- was to show that having an entity that users can refer to and acts as anchor, eases things. Now, for firewall rules, you'd probably have some other entity outside the pifs for that, (which could refer to the pifs if needed) indicating what traffic is allowed.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For, the rest, let's chat about it.

@mvachhar
Copy link
Contributor

mvachhar commented Mar 4, 2025

Also, can you give some examples of how you would use your approach to implement more complex things like firewall policies? And if we have different policies on different PIFs, how can you uniquely identify the PIF if multiple PIFs are using the same IP addresses.

@Fredi-raspall
Copy link
Author

Also, can you give some examples of how you would use your approach to implement more complex things like firewall policies? And if we have different policies on different PIFs, how can you uniquely identify the PIF if multiple PIFs are using the same IP addresses.

See above for the firewall. When you say that multiple PIFs use the same Ip address, can you give an example?

@Frostman Frostman marked this pull request as draft March 5, 2025 01:10
@mvachhar mvachhar closed this Mar 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants