-
Notifications
You must be signed in to change notification settings - Fork 6
GCP-388: No direct cross-cluster network connectivity #2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
GCP-388: No direct cross-cluster network connectivity #2
Conversation
Formalizes the rule that no cluster may establish direct TCP/UDP connections to another cluster's kube API by default. Covers component constraints (Terraform, ArgoCD, CLS/CLM) and SRE operational access patterns (no direct kubectl, break-glass only). Relates-to: GCP-388 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
@patjlm: This pull request references GCP-388 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
WalkthroughA new design decision document was added establishing a no-direct-cross-cluster-connectivity policy for GCP-HCP infrastructure. The policy forbids direct TCP/UDP cross-cluster connections by default across Global, Regional, and Management clusters, with exceptions only via controlled escalation, mandating indirect coordination mechanisms instead. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes 🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches🧪 Generate unit tests (beta)
No actionable comments were generated in the recent review. 🎉 Warning Review ran into problems🔥 ProblemsGit: Failed to clone repository. Please run the Comment |
|
/lgtm |
Summary
rc-mc-transport-layer.md,regional-independence-architecture.md) into a system-wide principleTest plan
design-decisions/TEMPLATE.mdchecklistrc-mc-transport-layer.mdandregional-independence-architecture.md🤖 Generated with Claude Code