Skip to content

Support for choosing the ingress class per component? #190

Open
@arner

Description

@arner

This would give the user more control over the networking policies and security.

Peers and orderers have to be exposed to the peers and orderers of the other organizations (either over a VPN or over the internet), but Certificate Authorities and the Console can usually stay private. And would be more secure to keep private. One way to manage it is to use two ingress controllers; one private and one public (or at least 'network public') - each of which exposed through a different loadbalancer with its own networking and firewall.

As far as I can tell it's not supported by the operator though; currently the ingressClass is hardcoded as nginx. Would it be possible (and feasible and desirable ;)) to make it configurable per component (e.g. supplying it in the config when deploying a peer)?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions