Mark Dittmer
Mark Dittmer
  • Видео 96
  • Просмотров 59 782
Implement Static Route Support for Flannel in Kubernetes
Say Goodbye to Tunnels: Using Static Routes in Kubernetes. This video demonstrates how simple integrating BIG-IP into Kubernetes using Flannel CNI and F5 CIS
GitHub: github.com/mdditt2000/kubernetes-1-31/tree/main/staticroutesupport/flannel#readme
Просмотров: 37

Видео

AS3 Editor on BIG-IP Next
Просмотров 11719 часов назад
This demo introduces the new AS3 editor available in BIG-IP Next
YouTube channel hit 1000 Subscribers!!! Thank You
Просмотров 11121 час назад
Just a quick note and thank for you for subscribing to my RUclips channel. Talk a little about whats coming next!
Efficiently Migrate Your App: CIS 2.x to CIS 3.x
Просмотров 1224 месяца назад
This demo shows how speedy application migration is from CIS 2.x to CIS 3.x
Enhancing NetOps and DevOps Collaboration with F5 BIG-IP Next and NGINX
Просмотров 2656 месяцев назад
This video demonstrates F5 IngressLink and elegant control plane solution that offers a unified method of working with both technologies from a single interface-offering the best of BIG-IP Next and NGINX and fostering better collaboration across NetOps and DevOps teams Github Repo github.com/mdditt2000/openshift-4-14/blob/main/ingresslink-cis-3-0/README.md
Integrating F5 CIS 3.0 with F5 BIG-IP Next in OpenShift
Просмотров 7206 месяцев назад
This demo provides a a step-by-step guide how F5 CIS 3.0 integrates with F5 BIG-IP Next. CIS is configured to detect the Node/Pods using NodePort Mode GitHub repo: github.com/mdditt2000/openshift-4-14/tree/main/cis3-0#readme
Exploring BIG-IP AS3 API Differences: Classic vs Next
Просмотров 4386 месяцев назад
This video demonstrates BIG-IP AS3 API Comparison: Classic vs Next Postman collection github.com/mdditt2000/f5-appsvcs-extension/tree/master/postman collection
Maximizing Scalability with F5 CIS: Blue-Green Deployment on OpenShift
Просмотров 2596 месяцев назад
This video demonstrates how F5 CIS can maximize scalability, providing a per-application, blue-green strategy using an OpenShift multi-cluster deployment GitHub repo: github.com/mdditt2000/openshift-4-14/tree/main/multi-cluster-blue-green#readme
Celebrating the 50th release of AS3
Просмотров 1648 месяцев назад
Today we release AS3-50. Celebrating the 5Oth release of AS3. That 2400 Jira tasks, 800 GitHub issues resolved and close. Amazing work to everybody involved.
F5 integration with RedHat Advanced Cluster Management for Multi-Cluster OpenShift
Просмотров 6088 месяцев назад
This document demonstrates how F5 can integrate with RedHat Advanced Cluster Management (ACM) in a OpenShift Multi-Cluster environment. This document focuses on deploying F5 Container Ingress Services (CIS) in then management cluster where ACM is deployed. CIS will monitor PODs deployed the worker clusters and orchestrate F5 BIG-IP to forward traffic to those PODs as shown in the diagram below:...
RedHat Advanced Cluster Manager Demo
Просмотров 1,6 тыс.8 месяцев назад
Demonstrating RedHat Advanced Cluster Manager with OpenShift 4.14
AS3 Per App API promoted from beta to general availability
Просмотров 3259 месяцев назад
This video demonstrator AS3 Per-App-API promotion from beta to general availability in AS3.50 release coming soon.
How was F5 Container Ingress Services used in 2023?
Просмотров 35211 месяцев назад
This demo shows how F5 CIS was used in 2023 from a CNI perspective and K8S configuration. GitHub repo: github.com/mdditt2000/k8s-bigip-ctlr/blob/main/user_guides/cis-usage-2023/README.md
Multi-Cluster NGINX Gateway API Fabric with F5 BIG-IP
Просмотров 42011 месяцев назад
This demo show how to reduce complexity for your Kubernetes apps with the Gateway API-conformant NGINX Gateway Fabric. Also using F5 BIG-IP and Container Ingress Services (CIS) to as the public entry point in a Multi-Cluster Kubernetes environment. GitHub repo: github.com/mdditt2000/k8s-bigip-ctlr/blob/main/user_guides/multi-cluster-nginx-gateway-fabric/README.md
NGINX Gateway API Fabric with F5 BIG-IP
Просмотров 73111 месяцев назад
This demo show how to reduce complexity for your Kubernetes apps with the Gateway API-conformant NGINX Gateway Fabric. Also using F5 BIG-IP and Container Ingress Services (CIS) to as the public entry point to the clusters. GitHub repo: github.com/mdditt2000/k8s-bigip-ctlr/blob/main/user_guides/nginx-gateway-fabric/README.md
Multi-Cluster Kubernetes using A/B Deployment
Просмотров 91811 месяцев назад
Multi-Cluster Kubernetes using A/B Deployment
Multi-Cluster OpenShift Ingress at KubeCon
Просмотров 419Год назад
Multi-Cluster OpenShift Ingress at KubeCon
Multi-cluster Kubernetes using F5 BIG-IP
Просмотров 907Год назад
Multi-cluster Kubernetes using F5 BIG-IP
Kubernetes Multi-Cluster Networking
Просмотров 1,5 тыс.Год назад
Kubernetes Multi-Cluster Networking
F5 BIG-IP AS3 API Best Practices - Part Two
Просмотров 703Год назад
F5 BIG-IP AS3 API Best Practices - Part Two
Introducing AS3 Per-Application API
Просмотров 694Год назад
Introducing AS3 Per-Application API
OpenShift Ingress in a Multi-Cluster World with NGINX + BIG-IP
Просмотров 1 тыс.Год назад
OpenShift Ingress in a Multi-Cluster World with NGINX BIG-IP
OpenShift Multi-Cluster Standalone using Cluster IP
Просмотров 459Год назад
OpenShift Multi-Cluster Standalone using Cluster IP
OpenShift Multi-Cluster Standalone using NodePort
Просмотров 644Год назад
OpenShift Multi-Cluster Standalone using NodePort
Using Journeys Tool to Migration Apps to F5 BIG-IP
Просмотров 2,6 тыс.Год назад
Using Journeys Tool to Migration Apps to F5 BIG-IP
Load Balancing apps between multiple OpenShift clusters using F5 BIG-IP
Просмотров 936Год назад
Load Balancing apps between multiple OpenShift clusters using F5 BIG-IP
A/B testing using the F5 BIG-IP Container Ingress Services
Просмотров 473Год назад
A/B testing using the F5 BIG-IP Container Ingress Services
Automating F5 BIG-IP Advanced WAF using AS3 API
Просмотров 483Год назад
Automating F5 BIG-IP Advanced WAF using AS3 API
Securing OpenShift with F5 BIG-IP Advanced WAF
Просмотров 389Год назад
Securing OpenShift with F5 BIG-IP Advanced WAF
Using F5 CIS to Configure Network when Integrating F5 BIG-IP with OpenShift
Просмотров 959Год назад
Using F5 CIS to Configure Network when Integrating F5 BIG-IP with OpenShift

Комментарии

  • @BhojpuriEmpire
    @BhojpuriEmpire 3 дня назад

    Thank you 1000 subscriber❤❤❤❤

  • @DojsFernando
    @DojsFernando 5 дней назад

    amazing videos! Congratulation

  • @joaoluiscamilo
    @joaoluiscamilo 5 дней назад

    I did not understand about the Advanced WAF Policy Profile definition. In a Production Openshift Cluster, does each App will have it's own custom WAF Policy or it's used a single Common WAF Policy for entire Openshift Cluster?

  • @TomCripps96
    @TomCripps96 8 дней назад

    Looks like video plays itself again after you’ve finished

  • @JohnSmith-dg3rd
    @JohnSmith-dg3rd 9 дней назад

    10x more deserved.

  • @vitusyu9583
    @vitusyu9583 16 дней назад

    Interesting! Is there a software version of F5 so that I can try your demo out in my lab?

    • @MarkDittmer
      @MarkDittmer 8 дней назад

      I would use CIS 2.18.1 with any version of BIG-IP. You will need AS3 plug AS-52

  • @benwyatt72
    @benwyatt72 Месяц назад

    Mark, is the WAF policy POSTed by AS3 or does the BIG-IP download the WAF policy from the URL?

    • @MarkDittmer
      @MarkDittmer 26 дней назад

      WAF policy is referenced on BIG-IP using a pointer. We could support a url download in the Policy CRD. Please submit a Github issue for this enhancement

  • @prashantbathula5448
    @prashantbathula5448 2 месяца назад

    What is the back end set up configured in f5 ?

    • @MarkDittmer
      @MarkDittmer 26 дней назад

      Backend? Please can you elaborate

  • @muhamadyusuphamdani9909
    @muhamadyusuphamdani9909 3 месяца назад

    If CNI use Flannel, its work? Or Change to calico?

    • @MarkDittmer
      @MarkDittmer 3 месяца назад

      Flannel is VXLAN based which requires tunnels between BIGIP and K8S. HA doesn’t work!! Recommend using Calico with static routing mode.. I have a video coming on how to set this up. It’s super simple. Calico using static routes on BIGIP was added in 2.17. Let me know how I can help

    • @muhamadyusuphamdani9909
      @muhamadyusuphamdani9909 3 месяца назад

      Thanks for the answer and the reason, I will try it first

    • @muhamadyusuphamdani9909
      @muhamadyusuphamdani9909 3 месяца назад

      I have single control plane with two worker at my existing cluster with CNI Falnnel. If i want to update to multiple control plane with load balancer F5, what i do and try? Detail k8s-cplane1 10.61.6.10 (existing) k8s-worker1 10.61.6.11 (existing) k8s-worker2 10.62.4.11 (existing) k8s-cplane2 10.62.4.10 (new) k8s-lb 10.0.32.41 (new)

    • @MarkDittmer
      @MarkDittmer 17 дней назад

      CIS is perfect for what you want todo. Deploy CIS and point to service in the cluster. You could use node port and node port labels to only service the 3 workers. Or clusterIP will work good to

    • @MarkDittmer
      @MarkDittmer 17 дней назад

      I believe you can use static routes with flannel. Email me at m.dittmer@f5.com and I will share the setup docs

  • @aquabat104
    @aquabat104 4 месяца назад

    Make an AS3 video focused on GTM/DNS Please!

    • @MarkDittmer
      @MarkDittmer 3 месяца назад

      Working on a Video today and tomorrow. Here is the declarations etc. github.com/mdditt2000/f5-appsvcs-extension/tree/master/demos/gslb -- Watch out for a video coming soon to RUclips

  • @alirizatasdemir6734
    @alirizatasdemir6734 4 месяца назад

    In a actual Project im planning a architecture concept for multi-cluster setup in active-active. Would nice to be have ure mind on it.

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      Please email me at m.dittmer@f5.com so we can setup a call

  • @alirizatasdemir6734
    @alirizatasdemir6734 4 месяца назад

    Great Presentation

  • @BAMFPodcast
    @BAMFPodcast 4 месяца назад

    did you find that Ansible Tower was required?

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      No, i wasn't aware of any Ansible Tower requirements. I will ask PM.

    • @BAMFPodcast
      @BAMFPodcast 4 месяца назад

      @@MarkDittmer looks like it’s bad information from an old doc.

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      let me know if you want to setup a meeting with the PM from OpenShift side.

  • @Egungon
    @Egungon 4 месяца назад

    Do you happen to have json declarations for creating wideIPs and/or GSLB pools via AS3?

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      thanks for the recommendation. I will work on this tomorrow. You ok with Generic Host instead of Virtual Server Discovery?

    • @Egungon
      @Egungon 4 месяца назад

      @@MarkDittmer that should be fine! Thanks!

  • @bernardocarcacheguerrero2297
    @bernardocarcacheguerrero2297 4 месяца назад

    Mark, can I manage only the WAF policies with this? I don’t want AS3 to manage my LTM objects.

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      AS3 can create a WAF policy from an external REPO as shown in the document. You could then add that policy to the LTM Virtual via the UI etc clouddocs.f5.com/training/fas-ansible-workshop-101/3.3-as3-asm.html --- This what you had in mind?

    • @bernardocarcacheguerrero2297
      @bernardocarcacheguerrero2297 4 месяца назад

      ⁠I am only looking to maintain the WAF policy, regardless of its Virtual Server assignment. I looked at the link and that creates the policy, but also assigns it to the Virtual Server. I don’t want that to happen. Can I use the “new_asm_policy” alone in an AS3 declaration?

  • @V.Z.69
    @V.Z.69 5 месяцев назад

    I just stumbled upon this page. Is the reference to "AS3" referring to "ActionScript 3" Adobe? And if so, are you using Flash with BIG-IP? Flash and AS3 was a game changer, too bad it's gone!!!

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      lol no AS3 is F5 BIG-IP Application Services 3 and has nothing todo with ActionScript 3.

  • @mohanbasava2115
    @mohanbasava2115 6 месяцев назад

    Can you explain from network connectivity’l persistive , big ip connects to physical switch and nodes are VM’s

    • @MarkDittmer
      @MarkDittmer 6 месяцев назад

      Can we schedule a meeting? I can demo the networking etc.

    • @mohanbasava2115
      @mohanbasava2115 6 месяцев назад

      @@MarkDittmer Sure Mark.. Let me know your availability we can sync up. I can explain my use case..

  • @arjund3772
    @arjund3772 6 месяцев назад

    Hi Mark, Can we configure Service Type LoadBalancer with OpenShift OVN-Kubernetes using F5 BIG-IP with NO Tunnels?

    • @MarkDittmer
      @MarkDittmer 6 месяцев назад

      yes, for Service Type LoadBalancer the CRD will require iPAM or a static IP to be populated for the public IP. Let me know if you need help setting this up. Contact me at m.dittmer@f5.com

  • @SqaTesting-c9e
    @SqaTesting-c9e 6 месяцев назад

    very informative

  • @Grzegorz_Wilczek
    @Grzegorz_Wilczek 6 месяцев назад

    Hi Mark, I can't find any info about schema version in NEXT, in Classic it'e easy as of plugin version, 3.0.0 is pretty old, how to get something newer in NEXT?

    • @MarkDittmer
      @MarkDittmer 6 месяцев назад

      Looking into this on Monday. Will message my team. Great question btw!!

    • @MarkDittmer
      @MarkDittmer 6 месяцев назад

      Just like with classic we don't actually use schema version other than to ensure a user doesn't send a declaration with a schema version newer than the latest supported on the given device. So just a matter of updating our examples which i will get posted in Clouddocs

    • @Grzegorz_Wilczek
      @Grzegorz_Wilczek 6 месяцев назад

      @@MarkDittmer Many thanks, I ask it in other way with an example. How do we know what version of AS3 we use in NEXT? Real example from last couple days.. We used 3.43 globally, but I started using Policy Endpoint with a new option "hostHeader" which was introduced in 3.47. In Classic I just need to roll out new rpm. How this work in NEXT and how do I know what AS3 version is installed?

  • @JohnSmith-dg3rd
    @JohnSmith-dg3rd 6 месяцев назад

    Thanks for the Postman Collection!

  • @JeffMorello
    @JeffMorello 6 месяцев назад

    Thanks for this video. Are you planning to do another one using an active/standby configuration?

    • @MarkDittmer
      @MarkDittmer 4 месяца назад

      Yes published here ruclips.net/video/EoWeMYhNTFY/видео.html -- Look at the weight in the route or CRD

  • @sh1k4maru
    @sh1k4maru 6 месяцев назад

    Great video as always

  • @JohnSmith-dg3rd
    @JohnSmith-dg3rd 7 месяцев назад

    Acces to Journeys over Browser is being refused.

    • @MarkDittmer
      @MarkDittmer 6 месяцев назад

      Try browser from the same next where you installed Journeys. I think this is a limitation of the OS. I will review emails to see if i can find a solution. I believe somebody figured it out

  • @GopalRoy-nn6ft
    @GopalRoy-nn6ft 7 месяцев назад

    What is cis?

    • @MarkDittmer
      @MarkDittmer 7 месяцев назад

      CIS is F5 BIG-IP Ingress Controller clouddocs.f5.com/containers/latest/

  • @sliddjur
    @sliddjur 7 месяцев назад

    Testing in AS3 v3.50, For anyone interested, perAppDeploymentAllowed is now a setting straight under settings and not nested under "betaOptions" {{baseUrl}}/mgmt/shared/appsvcs/settings { "asyncTaskStorage": "data-group", "perAppDeploymentAllowed": true, "burstHandlingEnabled": false, "performanceTracingEnabled": false, "performanceTracingEndpoint": "", "serializeFileUploads": false, "serviceDiscoveryEnabled": true, "webhook": "" }

    • @MarkDittmer
      @MarkDittmer 7 месяцев назад

      Enabled by default. Let me know your feedback and any improvements

  • @vagdemarrs
    @vagdemarrs 8 месяцев назад

    Congrats, thanks for the good work

  • @sliddjur
    @sliddjur 8 месяцев назад

    🎉😊

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      Thank you!!

    • @sliddjur
      @sliddjur 8 месяцев назад

      @@MarkDittmer what happened to v3.50? How about relasing binary, or giving us build instructions from source :)

  • @sliddjur
    @sliddjur 8 месяцев назад

    Ive been following your videos about as3 per app api, and now you suddenly changed your wording to resource group (aka tenant, aka partition) is the legacy way of doing everything? :) So you can not use /declare/tenant123/app and declare a single app, when tenant123 is not declared already? Also, how do you delete a single app?

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      thank you. No Per-app declaration must contain at least one application Declare one app in tenant123 and then you can POST to /declare/tenant123/applications/ with updates

  • @sliddjur
    @sliddjur 8 месяцев назад

    What about deleting a specific app?

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      Currently DELETE is not their. Something that could be added. Use POST Declare to remove any apps

  • @sliddjur
    @sliddjur 8 месяцев назад

    What is the reasoning why not per-app deployment was not the "best practice" and enabled by default from the beginning?

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      Good point. Because its only got added in AS3-50 coming next week.

  • @sliddjur
    @sliddjur 8 месяцев назад

    so if youre working on tenant2, and you forget to add to the URI declare/tenant2, you mess up all your other tenants?

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      Declarative. Declare the changes. Best to use via GitHub or Bitbucket

  • @aquabat104
    @aquabat104 8 месяцев назад

    When using AS3, should I have a separate tenant for each wide IP? So If I have 250 wide-ip's will I have 250 tenants? thank you

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      Wide-IPs are different when using AS3. I think generic-host for Wide-IPs is the way to go. Maybe common. I need to post a Best practice AS3 video for GSLB.

    • @aquabat104
      @aquabat104 7 месяцев назад

      @@MarkDittmerYes please we are migrating DNS module from on-prem to azure and want to use AS3 and frontend with terraform. About 500 wide-ip's

  • @arjund3772
    @arjund3772 8 месяцев назад

    Hi Mark, We can do this implementation with Openshift 4.12, right?

    • @MarkDittmer
      @MarkDittmer 8 месяцев назад

      Yes, absolutely, OpenShift 4.12 is perfectly fine!!

    • @arjund3772
      @arjund3772 6 месяцев назад

      @@MarkDittmer Hi Mark, Can we configure Service Type LoadBalancer with OpenShift OVN-Kubernetes using F5 BIG-IP with NO Tunnels?

  • @ZdenekZemba
    @ZdenekZemba 8 месяцев назад

    About 26:10 you say that if pool member is not unique then it has to be shared and placed to Common. In my case where have 2 partitions with own route-domains and own IP spaces and it happened that both uses 10.x.x.x and there are occasionally same pool members, does it mean that with AS3 I cannot have such setup and have to re-address the conflicting pool members? Adding them to Common is out of question as that uses route-domain 0...

    • @MarkDittmer
      @MarkDittmer 7 месяцев назад

      use share-nodes=true in the CIS deployment. This will create the pools members in the common partition. Example clouddocs.f5.com/containers/latest/userguide/config-parameters.html

    • @ZdenekZemba
      @ZdenekZemba 7 месяцев назад

      @@MarkDittmer as I mentioned, we use partitions with own routing domain, so placing pool member to Common will not make it work

    • @ZdenekZemba
      @ZdenekZemba 6 месяцев назад

      @@MarkDittmer I know this is not official communication channel, but I would appreciate answer to my question. Thanks

  • @kevinbrown7171
    @kevinbrown7171 9 месяцев назад

    I want to move our management of F5 to gitops, but we. have multiple vendors who currently request manual configuration of sets of Virtual servers for their respective API''s and each vendor has their own pipelines. I want to integrate each vendor to control their own API virtual servers into their respective pipelines, so no one vendor changes the entire config, but only a subset of virtual services, and also we have an operations team that need to control traffic management parameters between data centres. We have a common git repository. The most optimal pipeline is built with tecton and argocd, other are still with Jenkins but will migrate over time to a common set of pipelines using tecton and argocd. Is this possible using per app changes?

  • @quickref
    @quickref 9 месяцев назад

    We are currently preparing to migrate our existing f5 applications to AS3 and since we have some clusters with a lot of virtual servers, Per App will be helpful to keep a better control of our applications. Will there be an option to transform a ucs file with ACC to AS3 Per App? I'm planning to attend the Berlin App world. Will you be there, too?

    • @MarkDittmer
      @MarkDittmer 9 месяцев назад

      Journey's can consume the UCS file and represent the configuration as a per-app. But Journey's wont POST the the App back to BIG-IP using Per-APP. However this could be better implemented in the VScode extenetion. I am working with that team to get the Per-App API added to VScode

  • @JohnSmith-dg3rd
    @JohnSmith-dg3rd 9 месяцев назад

    I'm excited for BIG-IP Next. Finally something new.

    • @MarkDittmer
      @MarkDittmer 9 месяцев назад

      definitely. Lots of new content coming.

  • @amarganta5729
    @amarganta5729 9 месяцев назад

    Do we need to configure routing table on BIG-IP manually to direct traffic from BIG-IP to pods via Nodes?

    • @MarkDittmer
      @MarkDittmer 7 месяцев назад

      CIS will automate the routing table if you using OpenShift and some other CNIs.

  • @surrendermohan6520
    @surrendermohan6520 10 месяцев назад

    Thanks for the part2 video. How to have the AS3 API call work to apply only the incremental changes or per app changes where we have BIGIP-CIS controller running on kubernetes clusters which auto triggers these POST AS3 calls whenever there's changes on clusters.

    • @MarkDittmer
      @MarkDittmer 10 месяцев назад

      This is a change i want to get into CIS. We are waiting for AS3 Per APP API to go GA in AS3.50. This is planned in the upcoming months.

    • @surrendermohan6520
      @surrendermohan6520 10 месяцев назад

      @@MarkDittmer thank you

  • @KickstonesBitcoin
    @KickstonesBitcoin 10 месяцев назад

    How do you manage permissions per app? i only want admin from app team 1 to access API endpoint to make changes for app 1 and not app 2,3,4 etc

    • @MarkDittmer
      @MarkDittmer 10 месяцев назад

      Cant because the BIG-IP API doesnt provide the permission. This will be possible on BIG-IP Next using Per APP API.

  • @KickstonesBitcoin
    @KickstonesBitcoin 10 месяцев назад

    How can we control API user permissions to limit POSTS to per tenant or even better per app?

    • @MarkDittmer
      @MarkDittmer 9 месяцев назад

      AS3 has no RBAC on Classic. API user permissions to limit POSTS for AS3 is coming in BIG-IP Next. Please subscribe. I will create a demo for this in a month once the code is complete.

  • @shaikzoheb3430
    @shaikzoheb3430 11 месяцев назад

    You are just amazing Content is pure gold

  • @shaikzoheb3430
    @shaikzoheb3430 11 месяцев назад

    Amazing video. However I’m planning to use below tech stack. Is it possible to? Istio Ingress Gateway as Ingress Controller Calico/Cilium CNI Instead of nginx ingress, I wanted to use Istio as an ingress controller

    • @MarkDittmer
      @MarkDittmer 11 месяцев назад

      yes this is possible. i have seen some Istio. CIS just needs to monitor the Istio service. Calico or Cilium CNIs are both good options. Ping me if you need help

    • @shaikzoheb3430
      @shaikzoheb3430 11 месяцев назад

      @@MarkDittmer I’ve sent you an email for this. As I’m planning to use F5 BIG-IP, CIS for OpenShift Active Active Multi data centre deployment. Need to create an architecture and plan for this setup. Is there a way I can have a word with you?

    • @MarkDittmer
      @MarkDittmer 11 месяцев назад

      We are about to publish a document "F5 BIG-IP deployment with OpenShift - multi-cluster architectures" for your solution. Please contact me at m.dittmer@f5.com so we can schedule a zoom call

  • @shaikzoheb3430
    @shaikzoheb3430 11 месяцев назад

    How about OpenShift Ingress in a multi cluster with Istio ingress as a gateway. For those who are heavily using Istio. Is it possible ?

    • @MarkDittmer
      @MarkDittmer 26 дней назад

      using ServiceType LB? We are working on service type multicluster design this week and code available soon. Istio uses a HELM chart and has no CRD. Theirfore all needs to be specified in the service. Message me to get test image and docs.

  • @mohanbasava2115
    @mohanbasava2115 11 месяцев назад

    One question, why would External BIGIP needs to know Kubes routes in the routing table of BIGIP, assume since not directly connected to any of cluster, it can just follow the default route and upstream can handle routing part. ?

    • @MarkDittmer
      @MarkDittmer 26 дней назад

      CIS can create the routes for BIG-IP. Then BIG-IP simple route to the POD via the next hop "Node IP"

  • @mohanbasava2115
    @mohanbasava2115 11 месяцев назад

    This looks Cool. :-), We can properly segregate Apps within the tenants.

  • @backcountryFLcyclist
    @backcountryFLcyclist 11 месяцев назад

    Calico BGP, CRD, CIS Ingress Link with NGINX+ transport server and virtualserver is what I am seeing in production

    • @MarkDittmer
      @MarkDittmer 11 месяцев назад

      Thanks for your feedback. Definitely a sweet solution been able to use the best of both technology.

  • @growthandprogress689
    @growthandprogress689 11 месяцев назад

    I have one question, can ASM setting be adjusted in the AS3 declaration file or how can ASM setting be adjusted using AS3 on Vserver_tenant ?

    • @MarkDittmer
      @MarkDittmer 11 месяцев назад

      ASM policy should be modified in the ASM module or ASM API. AS3 will pull the latest policy and apply. AS3 simply references the profile/policy on the virtual for that tenant.

    • @growthandprogress689
      @growthandprogress689 11 месяцев назад

      @@MarkDittmer thanks for the reply, please can you make a video to demonstrate this setting or configuration thanks 🙏

    • @MarkDittmer
      @MarkDittmer 11 месяцев назад

      Will do. Per App Api will be GA in AS3 50. I will create another video for the release

  • @growthandprogress689
    @growthandprogress689 11 месяцев назад

    Thanks, for the updates.