Following #11765, I'd like to give the openshift pods in staging and prod read-only access to Fedora's NFS volumes containing the primary mirror:
I don't think there would be any security issue with this as it's a read-only access to something that we publish on the internet anyway. Could there be a significant risk of DOS maybe?
Unless I'm mistaken the Openshift IP range is 10.3.163.65-10.3.163.73 in prod and 10.3.166.50-10.3.166.58 in staging.
10.3.163.65
10.3.163.73
10.3.166.50
10.3.166.58
Metadata Update from @zlopez: - Issue priority set to: Waiting on Assignee (was: Needs Review) - Issue tagged with: high-gain, low-trouble, ops
Metadata Update from @kevin: - Issue assigned to kevin
ok. I added those for read-only access.
Metadata Update from @kevin: - Issue close_status updated to: Fixed with Explanation - Issue status updated to: Closed (was: Open)
Log in to comment on this ticket.