F5 BIG-IP deployment with Red Hat OpenShift - keeping client IP addresses and egress flows
Introduction
In this article it will be covered how to control the egress traffic in the Red Hat OpenShift cluster making use of the AdminPolicyBasedExternalRoute resource type introduced with Open...
Updated Jan 28, 2025
Version 2.0Ulises_Alonso
Employee
Solutions architect in Business Development with focus in automation and integration with partner's technologies. Prior to this role I was consultant in Professional Services and escalations engineer in Technical Support. Outside F5, I worked in mobile and wired network operators as network engineer. I started my career in academic research. In all these years, no matter what I've been doing Linux has been always the best tool.
Not the one in the picture :-)PaulVogt
Altocumulus
Mar 15, 2025This works nicely, but it requires an interface per gateway. If you want to use the AdminPolicyBasedExternalRoute option to achieve an egress ip address per namespace, you run quickly out of interfaces.
Ulises_Alonso
Employee
Jul 22, 2025I´m checking the feasibility of using AdminPolicyBasedExternalRoute with User Defined Networking (CUDN/UDN). If both OpenShift functionalities play together then we could have a single egress VIP which uses the source IP to assign the SNAT.
Would OpenShift CUDN/UDN play well in your scenario? https://www.youtube.com/watch?v=Xh6JvqSPM8c