Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add DNAT rule to Azure Firewall during post deploy #565

Open
Gordonby opened this issue Mar 29, 2023 · 1 comment
Open

Add DNAT rule to Azure Firewall during post deploy #565

Gordonby opened this issue Mar 29, 2023 · 1 comment
Labels
enhancement New feature or request help wanted Extra attention is needed Keep Open

Comments

@Gordonby
Copy link
Collaborator

Gordonby commented Mar 29, 2023

Is your feature request related to a problem? Please describe.
If the user has selected Azure Firewall + Ingress (Contour/Nginx/Traefik) selected, they will need a DNAT rule added to the Firewall for the ingress to be properly exposed.

Describe the solution you'd like
We could create this configuration during post-deploy after the IP for the ingress controller is known.
If the user is using a dedicated subnet for ingress controller IP's (#552) then we could even do this all in the bicep as we'll be able to assume the IP.

Describe alternatives you've considered
Creating it manually.

Additional context
https://learn.microsoft.com/en-gb/azure/aks/limit-egress-traffic#add-a-dnat-rule-to-azure-firewall

@Gordonby Gordonby added the enhancement New feature or request label Mar 29, 2023
@github-actions
Copy link
Contributor

Issue smells stale, no activity for 30 days. Stale Label will be removed if the issue is updated, otherwise closed in a month.

@github-actions github-actions bot added the stale An issue that hasn't had a lot of love recently label Apr 28, 2023
@Gordonby Gordonby added help wanted Extra attention is needed Keep Open and removed stale An issue that hasn't had a lot of love recently labels Apr 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed Keep Open
Projects
None yet
Development

No branches or pull requests

1 participant