Changes to Application Kubernetes Service Access

更新时间:
复制 MD 格式

Background

Due to new access restrictions for Alibaba Cloud Container Service for Kubernetes (ACK), the method that Application Kubernetes Service (AKS) on the SOFAStack platform uses to access your ACK clusters will change. You must perform the required actions to adapt to this change.

Note
  • Please complete the required adjustments by August 31, 2024. Failure to do so will affect the normal operation of the containerized application service product.

  • This change does not affect users of the Multi-cluster Container Engine product.

Options

SOFAStack provides two options:

Option 1: Connect to ACK clusters over the public network

The following section describes the operations.

  1. Log on to the ACK console to enable a public kubeconfig for your cluster.

  2. Log on to the SOFAStack console, and on the Cluster Details page, click Update KubeConfig to update the kubeconfig in the SOFAStack Container Application Service.

After you complete these steps, SOFAStack can access your ACK cluster directly over the public network.

Note
  • The Update KubeConfig feature will be available on August 27, 2024.

  • SOFAStack provides a list of public egress IP addresses. Add these addresses to your public network Access Control List (ACL) whitelist. To obtain this list, submit a ticket to the SOFAStack technical support team.

  • This option requires you to enable public network access and will incur additional charges. For more information, see Access the API server over the public network.

Option 2: Migrate to the Multi-cluster Container Engine product

The Multi-Cluster Container Engine product on the SOFAStack platform launched in 2021 as the next-generation containerized application product, replacing the Container Application Service. Because it natively supports multi-cluster capabilities, it is not affected by this change. For more information, see Multi-Cluster Container Engine.