Original Message:
Sent: 9/3/2024 10:07:00 AM
From: David Miller
Subject: RE: MAS9 SNO and how to setup Port Forwarding on Router to make accessible from Internet?
I really appreciate your help on me getting my MAS environment accessible to the internet. I am trying your suggestion with Port Forwarding and I am breaking things left and right.
We seemed to have overlooked the RHOCP Control Panel access in your suggestions and more important is my LetsEncrypt SSL Cert that are also in place for the internal network. As soon as I made your suggestions I lost access to the Control Panel and in fact could not even log in any longer with the oc login command line. So, I added an entry back for 192.1.1.x to my DNS for the api.eipdemo.mydomain.com and that got my control panel access back and oc login. But I could not get into MAS as a SSL error. So I am trying to redo my certbot setting with the new DNS entries out on Cloudflare. I am not clear what I need to do with the api.eipdemo.mydomain.com entry should it be my 192. addy or should I make that my internet address? Also, should I not have an A entry for mydomain.com set to my internet addy as well?
I also think we overlooked the 80,6443,8443,8080 in my port forwarding of my router and I am not sure if I need those or not? I have added them thinking they would be needed.
Also once I do get my SSL certs resolved I am assuming I will need to get into the console and change my secrets to Maximo before i will ever be able to get in? Would you not agree?
Again, very appreciative of help but feel we left a lot of unknowns out there. Not quite as simple as you made it sound when I have SSL at play and the console access seems to have been forgotten?
I am totally hosed again now with no access to even my console due to the letsencrypt stuff. I am trying to give it some time and see if it comes back around but worried I may have really broke stuff now. But it may be a cascade of errors starting at SSL but then at my DNS entries and my port forwarding rules.
My api.eipdemo.mydomain.com right now is pinging to a 104.21.1.x address right now so I assume that is huge problem... I have no idea where that addy is coming from
------------------------------
David Miller
Managing Partner - Maximo Consultant
Enterprise Integration Partners LLC
------------------------------
Original Message:
Sent: Mon September 02, 2024 07:03 AM
From: Jason Pun
Subject: MAS9 SNO and how to setup Port Forwarding on Router to make accessible from Internet?
Hi David
I had installed mange SNO in my home lab as well, may share some experience on my network and MAS configure, and I am using 2 difference domain name for my OpenShift and MAS
- I am using Cloudflare to hold my domain name, let say mymas.com and I added 2 A record 1 is *, another is the domain name mymas.com, the IP address is my internet IP
- In my router configure port forwarding 443 to my SNO server
- When install MAS, do not configure domain and certificate management
- Change MAS domain and using Let's Encrypt for my MAS domain mymas.com
Regards,
------------------------------
Jason Pun
Technical Consulant
Original Message:
Sent: Sun September 01, 2024 06:21 PM
From: David Miller
Subject: MAS9 SNO and how to setup Port Forwarding on Router to make accessible from Internet?
So I tried to change the DNS Entries only to my public IP address values and that broke all as my LetsEncrypt is tied to those values. So, I am guessing I would need to redo all my LetsEncrypt stuff if I make that change? I was luck y to be able to put it all back and I went back to working. So, I do not want to go through all the LetsEncrypt setup with my public IP address if is not going to work. Hoping someone can tell me if that is the solution or not. Anyone else deal with this or try this yet?
------------------------------
David Miller
Managing Partner - Maximo Consultant
Enterprise Integration Partners LLC
Original Message:
Sent: Sun September 01, 2024 06:04 PM
From: David Miller
Subject: MAS9 SNO and how to setup Port Forwarding on Router to make accessible from Internet?
So, I have a MAS9 SNO setup running on a server in my home office and I am trying to figure how to make it accessible from the internet. I bought a domain that it was all setup through. So my login goes to (https://auth.inst1.apps.eipdemo.mydomain.com/) I am bit confused as my Cloudflare settings have the 192.168.1.x for the following:
A api.eipdemo - 192.168.1.x
A api-int.eipdemo - 192.168.1.x
A *.apps.eipdemo - 192.168.1.x
A mydomain.com - my external ip
CNAME do - mydomain.com
CNAME www - mydomain.com
And then my router is already doing Port Forwarding
HTTPS 443 443 192.168.1.x
HTTP 80 80 192.168.1.x
OCP API Management port 6443 6443 192.168.1.x
OCP Management 8443 8443 192.168.1.x
OCP Management HTTPS 8080 8080 192.168.1.x
Totally lost what I need to do to my DNS registration to start tying it to my external IP and make the Port Forwarding work when I come in from outside. I have a DDNS registration with NO-IP (myddns.mynetgear.com) some how I am assuming I would come in through that but that then confuses me on what to do with my domain name that I own and can I use that on the web instead of the DDNS?
Can I bypass the DDNS and simply make my DNS entries use my real IP Address for all the 192.168.1.x values above and the Port Forwarding will take over to route me through the subdomains that the MAS uses once I log in and start navigating around? My ISP has given me the same IP address for years so I am not sure it changes much if at all. My thoughts are changing it on Cloudflare would be no big deal if it changed on me again if that is only place I need to make the changes.
If I change the IP address on the DNS entries will my internal router do forwarding to the 192.168.1.x and make this all work?
Very confused what to change and how best to do this. Google leads me into all kinds of pages about changing routing tables in OpenShift and setting up port forwarding in OpenShift as to get to Pods and such and seems way more involved then I hope it needs to be when I have a Router that should be able to do this for me.
Please help if you can. Totally Confused
Thanks,
------------------------------
David Miller
Managing Partner - Maximo Consultant
Enterprise Integration Partners LLC
------------------------------