|
| 1 | +--- |
| 2 | +title: Connectivity |
| 3 | +weight: 15 |
| 4 | +aliases: /ramendr-starter-kit/connectivity/ |
| 5 | +--- |
| 6 | + |
| 7 | +:toc: |
| 8 | +:imagesdir: /images |
| 9 | +:_content-type: ASSEMBLY |
| 10 | +include::modules/comm-attributes.adoc[] |
| 11 | + |
| 12 | +[id="ramendr-connectivity"] |
| 13 | += Hub-to-managed connectivity |
| 14 | + |
| 15 | +Three install variants (`main.variant` in `values-global.yaml`): |
| 16 | + |
| 17 | +* **odf** (default) — full {ocp-data-short} Regional DR; MCG S3 on managed clusters; Submariner required for Ceph RBD replication |
| 18 | +* **drpartner-s4** — partner CSI + hub S4; array-native volume replication; **Submariner disabled** (`submariner.enabled: false` in `opp-policy`) |
| 19 | +* **drpartner-minimal** — partner CSI operators and Hive/BYOC plumbing only; no S4, DRClusters, or Submariner |
| 20 | + |
| 21 | +Draw.io source with one tab per variant: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`]. |
| 22 | + |
| 23 | +[id="variant-comparison"] |
| 24 | +== Variant comparison |
| 25 | + |
| 26 | +[cols="2,1,1,1",options="header"] |
| 27 | +|=== |
| 28 | +| Concern | odf | drpartner-s4 | drpartner-minimal |
| 29 | + |
| 30 | +| S3 / DR metadata | MCG buckets on each managed cluster | Hub S4 buckets (`vp-s4-storage`) | None |
| 31 | +| Hub S3 reachability | Hub → each managed MCG endpoint | Hub + managed → hub S4 | n/a |
| 32 | +| Peer S3 | Managed ↔ managed object-bucket metadata | Not used | Not used |
| 33 | +| Volume replication | {ocp-data-short}/Ceph over Submariner | VSA ↔ VSA (array-native) | External / out of pattern |
| 34 | +| Submariner | Required for Regional-DR volumes | **Disabled by default** | **Disabled** |
| 35 | +| DRClusters / DRPolicy | MirrorPeer / MCO / regionaldr | regionaldr (`infrastructureEnabled`) | None |
| 36 | +| DRPC / VMs | Yes (regionaldr resources) | No (`resourcesEnabled: false`) | No |
| 37 | +| {rh-rhacm} + DNS | Required | Required | Required |
| 38 | +|=== |
| 39 | + |
| 40 | +[id="connectivity-odf"] |
| 41 | +== `odf` |
| 42 | + |
| 43 | +{rh-rhacm-first} needs DNS resolvability of managed cluster APIs. S3 metadata buckets (MCG) live **on each managed cluster** — hub and peers both reach those endpoints. **Submariner is required** for {ocp-data-short} RBD cross-site replication. |
| 44 | + |
| 45 | +.ramendr-hub-managed-connectivity-odf |
| 46 | +image::/images/ramendr-starter-kit/hub-managed-connectivity-odf.png[odf hub-to-managed connectivity,title="odf connectivity"] |
| 47 | + |
| 48 | +draw.io source: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] (**odf** tab). |
| 49 | + |
| 50 | +[id="managed-mcg-s3-detail"] |
| 51 | +=== Managed MCG S3 detail |
| 52 | + |
| 53 | +++++ |
| 54 | +<pre class="mermaid"> |
| 55 | +flowchart LR |
| 56 | + Hub["Ramen Hub Operator"] --> MCG1["Primary MCG S3"] |
| 57 | + Hub --> MCG2["Secondary MCG S3"] |
| 58 | + MCG1 ---|"Peer metadata"| MCG2 |
| 59 | +</pre> |
| 60 | +++++ |
| 61 | + |
| 62 | +[id="connectivity-drpartner-s4"] |
| 63 | +== `drpartner-s4` |
| 64 | + |
| 65 | +{rh-rhacm-first} needs DNS resolvability of managed cluster APIs. S3 metadata lives on **hub S4** (`vp-s4-storage`). Volume DR is array-native (VSA ↔ VSA). The `regional-dr` application creates hub DRClusters and a `2m-novm` DRPolicy only — no DRPC or VMs. **Submariner is not deployed** (`values-opp-policy.yaml` sets `submariner.enabled: false`). |
| 66 | + |
| 67 | +.ramendr-drpartner-s4-connectivity |
| 68 | +image::/images/ramendr-starter-kit/drpartner-s4-connectivity.png[drpartner-s4 hub-to-managed connectivity,title="drpartner-s4 connectivity"] |
| 69 | + |
| 70 | +PNG from draw.io: link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-s4.png[`hub-managed-connectivity-drpartner-s4.png`]. SVG source: link:/images/ramendr-starter-kit/drpartner-s4-connectivity.svg[`drpartner-s4-connectivity.svg`]. draw.io source: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] (**drpartner-s4** tab). |
| 71 | + |
| 72 | +[id="hub-s4-detail"] |
| 73 | +=== Hub S4 detail |
| 74 | + |
| 75 | +++++ |
| 76 | +<pre class="mermaid"> |
| 77 | +flowchart LR |
| 78 | + Ramen["Ramen Hub Operator"] --> S4["Hub S4 buckets"] |
| 79 | + P["Primary DR operator"] --> S4 |
| 80 | + S["Secondary DR operator"] --> S4 |
| 81 | +</pre> |
| 82 | +++++ |
| 83 | + |
| 84 | +No managed ↔ managed S3 and no Submariner in `drpartner-s4`. |
| 85 | + |
| 86 | +[id="connectivity-drpartner-minimal"] |
| 87 | +== `drpartner-minimal` |
| 88 | + |
| 89 | +{rh-rhacm-first} needs DNS resolvability of managed cluster APIs. The pattern deploys partner operators (MCO/Ramen, {VirtProductName}, OADP) and Hive/BYOC plumbing only — **no `vp-s4-storage`**, no DRClusters, no `s3StoreProfiles`, and **no Submariner**. Volume DR and S3 metadata are outside this pattern. |
| 90 | + |
| 91 | +.ramendr-drpartner-minimal-connectivity |
| 92 | +image::/images/ramendr-starter-kit/drpartner-minimal-connectivity.png[drpartner-minimal hub-to-managed connectivity,title="drpartner-minimal connectivity"] |
| 93 | + |
| 94 | +PNG from draw.io: link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-minimal.png[`hub-managed-connectivity-drpartner-minimal.png`]. SVG source: link:/images/ramendr-starter-kit/drpartner-minimal-connectivity.svg[`drpartner-minimal-connectivity.svg`]. draw.io source: link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] (**drpartner-minimal** tab). |
| 95 | + |
| 96 | +[id="shared-requirements"] |
| 97 | +== Shared requirements |
| 98 | + |
| 99 | +* **{rh-rhacm} + DNS** — Hub must resolve each managed cluster API hostname, then connect over HTTPS 443 / kube API 6443. |
| 100 | +* **TLS / CA trust** — Trust custom certs for S4 (`drpartner-s4`) or MCG endpoints (`odf`) via `opp-policy` `s3CaInjector` where S3 is used. |
| 101 | +* **Globalnet** — For `odf`, enable if managed cluster/service CIDRs overlap. |
| 102 | + |
| 103 | +[id="ports"] |
| 104 | +== Ports |
| 105 | + |
| 106 | +[cols="2,2,2",options="header"] |
| 107 | +|=== |
| 108 | +| Path | When | Protocol / ports |
| 109 | + |
| 110 | +| Hub DNS → managed API | All variants | DNS UDP/TCP 53 |
| 111 | +| Hub ↔ managed API | All variants | HTTPS 443; kube API 6443 |
| 112 | +| Clients → hub S4 | `drpartner-s4` | HTTPS 443 |
| 113 | +| Hub / peers → managed MCG | `odf` | HTTPS 443 |
| 114 | +| Cluster ↔ local VSA | `drpartner-s4`, `drpartner-minimal` | Vendor CSI / iSCSI / NVMe / mgmt |
| 115 | +| VSA ↔ VSA replication | `drpartner-s4`, `drpartner-minimal` | Vendor replication ports |
| 116 | +| Submariner | `odf` only | UDP 4500 / 4800 / 4490 |
| 117 | +|=== |
| 118 | + |
| 119 | +[id="related-diagrams"] |
| 120 | +== Related diagrams |
| 121 | + |
| 122 | +[cols="2,2,2",options="header"] |
| 123 | +|=== |
| 124 | +| Artifact | PNG | draw.io / other |
| 125 | + |
| 126 | +| Full component schematic (`odf`) |
| 127 | +| link:/images/ramendr-starter-kit/ramendr-architecture-odf.png[`ramendr-architecture-odf.png`] |
| 128 | +| link:/images/ramendr-starter-kit/ramendr-architecture-odf.drawio[`ramendr-architecture-odf.drawio`] |
| 129 | + |
| 130 | +| Full component schematic (`drpartner-s4`) |
| 131 | +| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.png[`ramendr-architecture-drpartner-s4.png`] |
| 132 | +| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-s4.drawio[`ramendr-architecture-drpartner-s4.drawio`] |
| 133 | + |
| 134 | +| Full component schematic (`drpartner-minimal`) |
| 135 | +| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.png[`ramendr-architecture-drpartner-minimal.png`] |
| 136 | +| link:/images/ramendr-starter-kit/ramendr-architecture-drpartner-minimal.drawio[`ramendr-architecture-drpartner-minimal.drawio`] |
| 137 | + |
| 138 | +| Connectivity overview (`odf`) |
| 139 | +| link:/images/ramendr-starter-kit/hub-managed-connectivity-odf.png[`hub-managed-connectivity-odf.png`] |
| 140 | +| link:/images/ramendr-starter-kit/hub-managed-connectivity.drawio[`hub-managed-connectivity.drawio`] |
| 141 | + |
| 142 | +| Connectivity overview (`drpartner-s4`) |
| 143 | +| link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-s4.png[`hub-managed-connectivity-drpartner-s4.png`] |
| 144 | +| link:/images/ramendr-starter-kit/drpartner-s4-connectivity.svg[`drpartner-s4-connectivity.svg`] |
| 145 | + |
| 146 | +| Connectivity overview (`drpartner-minimal`) |
| 147 | +| link:/images/ramendr-starter-kit/hub-managed-connectivity-drpartner-minimal.png[`hub-managed-connectivity-drpartner-minimal.png`] |
| 148 | +| link:/images/ramendr-starter-kit/drpartner-minimal-connectivity.svg[`drpartner-minimal-connectivity.svg`] |
| 149 | +|=== |
| 150 | + |
| 151 | +See also link:/patterns/ramendr-starter-kit/architecture/[Architecture] for TLS/CA handling and full schematic context. |
0 commit comments