This document aims to provide information how to setup your workstation
to access to the resources in the project. You already should have SSH
public and private keys in place created by using the command
ssh-keygen
on your workstation and also one on the bastion workstation
VM. If not done yet, please follow the Red Hat
documentation
to generate one with elliptic curves like ECDSA.
Please add following configuration on you SSH Config file which is
usually ~/.ssh/config
.
# Bastion Config
Host <bastion_vm_fqdn>
HostName <bastion_vm_fqdn>
IdentityFile ~/.ssh/id_ecdsa
port 22
ServerAliveInterval 300
ServerAliveCountMax 2
User <your_username>
UserKnownHostsFile /dev/null
# SSH Clients
Host *.<project_fqdn>
ProxyJump <bastion_vm_fqdn>
User <your_username>
IdentityFile ~/.ssh/id_ecdsa
ServerAliveInterval 300
ServerAliveCountMax 2
UserKnownHostsFile /dev/null
This configuration will allow you to access all the resources in a protected environment over SSH using Bastion Jumphost VM like in your local network.
The following configuration will help you to configure your workstation access to the project resources with WebUI using a proxy on the Bastion Jumphost VM. When configured you can access to the resources using their local IP addresses or fully qualified domain name.
It is recommended to use a browser extension for automatically switching between the proxies or direct access based on the rules for not affecting your existing access definitions. The web resources in the project could not exposed on Internet which you can not directly access without using the configuration steps below.
- Deploy browser extension named
Switchy Omega Extension
. - Open the extension Options to configure a new profile with a name
rhis-bastion
andProxy Profile
option. - Navigate to the newly created profile and add
_<bastion_vm_fqdn>_
to the servers list with a proxy port number3128
for HTTP access in default scheme. - Navigate to the ˙auto switch˙ profile and add add switch rules to use with
Condition Type
equalHost Wildcard
,Condition Details
equal_<project_fqdn>_
andprofile
equal torhis-bastion
. - Ensure from the browser extension that
auto switch
profile set as default.
This setup will allow you to access WebUI's of the any application on the project.