Skip to content

Private Link for upstream CAPZ #2042

@Rotfuks

Description

@Rotfuks

Motivation

In #2011 we learned that we can improve the security and stability of our private network workload clusters by introducing private links to upstream capz. With that we can easily connect to workload clusters private endpoints and don't have to care too much about overlapping IP addresses.

Todo

- [x] Investigate the state of private endpoints / private link in upstream
- [x] Create an issue to propose and discuss private link as a new feature in upstream https://github.com/kubernetes-sigs/cluster-api-provider-azure/issues/3400
- [x] Implement private link in our CAPZ fork https://github.com/giantswarm/cluster-api-provider-azure/pull/17
- [ ] Update CAPZ app https://github.com/giantswarm/cluster-api-provider-azure-app/pull/104
- [ ] Update cluster-azure app https://github.com/giantswarm/cluster-azure/pull/115

Outcome

  • We can easily and securely connect management clusters with workload clusters in a private network configuration

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

Status
In Progress ⛏️

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions