Uploaded image for project: 'ONAP Operations Manager'
  1. ONAP Operations Manager
  2. OOM-1508

Integrate Ingress Controller into ONAP Cluster

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Medium Medium
    • Frankfurt Release
    • None
    • None

      In Casablanca there are over 100 NodePorts externally accessible to an ONAP Cluster. Not only is this unnecessary and unmanageable but it poses a security risk with so many potential points of attack. By using an Ingress Controller to handle northbound traffic coming into and out of a k8s cluster, we dramatically reduce the attack surface and have a much simpler means of accessing deployed services within the cluster.

      One such Ingress Controller (reverse proxy/load balancer) is the Ambassador Envoy Proxy. It is the same one used by Istio for which we may need to integrate with for TLS connectivity and certificate management.

      More info in separate tasks related to the ISTIO and NGINX

            lucjan.bryndza.s lucjan.bryndza.s
            melliott melliott
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: