Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possibility of adding custom routes to routing table (Traffic routing control for egress) #1008

Open
waheedshahani opened this issue Jul 16, 2024 · 0 comments
Labels
area/networking Networking related kind/enhancement Enhancement, improvement, extension platform/aws Amazon web services platform/infrastructure

Comments

@waheedshahani
Copy link

How to categorize this issue?
/area networking
/kind enhancement
/platform aws

What would you like to be added:
When a shoot cluster is created, user shall have possibility to add custom routes (e.g default route) so that one can divert egress traffic for cluster to another VPC/VPG/Transit Gateway in another VPC or firewall instances in same VPC. When custom route for default route is provided then Gardener shall not create any NATGW as it shall rely on existing routing to provide internet connectivity to Gardener seed.

Why is this needed:
By default Gardener creates NAT GW and default routes point to NATGW which allow unrestricted internet access to shoot clusters. This is security risk for many types of deployments where user wants to egress traffic via predefined firewall instances or other VPCs.

@gardener-robot gardener-robot added area/networking Networking related kind/enhancement Enhancement, improvement, extension platform/aws Amazon web services platform/infrastructure labels Jul 16, 2024
@waheedshahani waheedshahani changed the title Possibility of additing custom routes to routing table (Traffic routing control for egress) Possibility of adding custom routes to routing table (Traffic routing control for egress) Oct 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/networking Networking related kind/enhancement Enhancement, improvement, extension platform/aws Amazon web services platform/infrastructure
Projects
None yet
Development

No branches or pull requests

2 participants