You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/azure-arc/resource-bridge/system-requirements.md
+22-24Lines changed: 22 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,17 +39,19 @@ These minimum requirements enable most scenarios. However, a partner product may
39
39
40
40
## IP address prefix (subnet) requirements
41
41
42
-
The IP address prefix (subnet) where Arc resource bridge will be deployed requires a minimum prefix of /29. The IP address prefix must have enough available IP addresses for the gateway IP, control plane IP, appliance VM IP, and reserved appliance VM IP. Please work with your network engineer to ensure that there is an available subnet with the required available IP addresses and IP address prefix for Arc resource bridge.
42
+
The IP address prefix (subnet) where Arc resource bridge will be deployed requires a minimum prefix of /29. The IP address prefix must have enough available IP addresses for the gateway IP, control plane IP, appliance VM IP, and reserved appliance VM IP. Arc resource bridge only uses the IP addresses assigned to the IP pool range (Start IP, End IP) and the Control Plane IP. We recommend that the End IP immediately follow the Start IP. Ex: Start IP =192.168.0.2, End IP = 192.168.0.3. Please work with your network engineer to ensure that there is an available subnet with the required available IP addresses and IP address prefix for Arc resource bridge.
43
43
44
-
The IP address prefix is the subnet's IP address range for the virtual network and subnet mask (IP Mask) in CIDR notation, for example `192.168.7.1/24`. You provide the IP address prefix (in CIDR notation) during the creation of the configuration files for Arc resource bridge.
44
+
The IP address prefix is the subnet's IP address range for the virtual network and subnet mask (IP Mask) in CIDR notation, for example `192.168.7.1/29`. You provide the IP address prefix (in CIDR notation) during the creation of the configuration files for Arc resource bridge.
45
45
46
46
Consult your network engineer to obtain the IP address prefix in CIDR notation. An IP Subnet CIDR calculator may be used to obtain this value.
47
47
48
48
## Static IP configuration
49
49
50
50
If deploying Arc resource bridge to a production environment, static configuration must be used when deploying Arc resource bridge. Static IP configuration is used to assign three static IPs (that are in the same subnet) to the Arc resource bridge control plane, appliance VM, and reserved appliance VM.
51
51
52
-
DHCP is only supported in a test environment for testing purposes only for VM management on Azure Stack HCI, and it should not be used in a production environment. DHCP isn't supported on any other Arc-enabled private cloud, including Arc-enabled VMware, Arc for AVS, or Arc-enabled SCVMM. If using DHCP, you must reserve the IP addresses used by the control plane and appliance VM. In addition, these IPs must be outside of the assignable DHCP range of IPs. Ex: The control plane IP should be treated as a reserved/static IP that no other machine on the network will use or receive from DHCP. If the control plane IP or appliance VM IP changes (ex: due to an outage, this impacts the resource bridge availability and functionality.
52
+
DHCP is only supported in a test environment for testing purposes only for VM management on Azure Stack HCI. It should not be used in a production environment. DHCP isn't supported on any other Arc-enabled private cloud, including Arc-enabled VMware, Arc for AVS, or Arc-enabled SCVMM.
53
+
54
+
If using DHCP, you must reserve the IP addresses used by the control plane and appliance VM. In addition, these IPs must be outside of the assignable DHCP range of IPs. Ex: The control plane IP should be treated as a reserved/static IP that no other machine on the network will use or receive from DHCP. If the control plane IP or appliance VM IP changes, this impacts the resource bridge availability and functionality.
53
55
54
56
## Management machine requirements
55
57
@@ -58,10 +60,14 @@ The machine used to run the commands to deploy and maintain Arc resource bridge
- Open communication to Control Plane IP (`controlplaneendpoint` parameter in `createconfig` command)
62
-
- Open communication to Appliance VM IP
63
-
- Open communication to the reserved Appliance VM IP
64
-
- if applicable, communication over port 443 to the private cloud management console (ex: VMware vCenter host machine)
63
+
- Open communication to Control Plane IP
64
+
65
+
- Communication to Appliance VM IP (SSH TCP port 22, Kubernetes API port 6443)
66
+
67
+
- Communication to the reserved Appliance VM IP ((SSH TCP port 22, Kubernetes API port 6443)
68
+
69
+
- communication over port 443 (if applicable) to the private cloud management console (ex: VMware vCenter host machine)
70
+
65
71
- Internal and external DNS resolution. The DNS server must resolve internal names, such as the vCenter endpoint for vSphere or cloud agent service endpoint for Azure Stack HCI. The DNS server must also be able to resolve external addresses that are [required URLs](network-requirements.md#outbound-connectivity) for deployment.
66
72
- Internet access
67
73
@@ -77,11 +83,8 @@ Appliance VM IP address requirements:
77
83
78
84
- Open communication with the management machine and management endpoint (such as vCenter for VMware or MOC cloud agent service endpoint for Azure Stack HCI).
79
85
- Internet connectivity to [required URLs](network-requirements.md#outbound-connectivity) enabled in proxy/firewall.
80
-
- Static IP assigned (strongly recommended)
86
+
- Static IP assigned and within the IP address prefix.
81
87
82
-
- If using DHCP, then the address must be reserved and outside of the assignable DHCP range of IPs. No other machine on the network will use or receive this IP from DHCP. DHCP is generally not recommended because a change in IP address (ex: due to an outage) impacts the resource bridge availability.
83
-
84
-
- Must be from within the IP address prefix.
85
88
- Internal and external DNS resolution.
86
89
- If using a proxy, the proxy server has to be reachable from this IP and all IPs within the VM IP pool.
87
90
@@ -99,15 +102,11 @@ Reserved appliance VM IP requirements:
99
102
100
103
- Internet connectivity to [required URLs](network-requirements.md#outbound-connectivity) enabled in proxy/firewall.
101
104
102
-
- Static IP assigned (strongly recommended)
103
-
104
-
- If using DHCP, then the address must be reserved and outside of the assignable DHCP range of IPs. No other machine on the network will use or receive this IP from DHCP. DHCP is generally not recommended because a change in IP address (ex: due to an outage) impacts the resource bridge availability.
105
-
106
-
- Must be from within the IP address prefix.
105
+
- Static IP assigned and within the IP address prefix.
107
106
108
-
- Internal and external DNS resolution.
107
+
- Internal and external DNS resolution.
109
108
110
-
- If using a proxy, the proxy server has to be reachable from this IP and all IPs within the VM IP pool.
109
+
- If using a proxy, the proxy server has to be reachable from this IP and all IPs within the VM IP pool.
111
110
112
111
## Control plane IP requirements
113
112
@@ -117,8 +116,7 @@ Control plane IP requirements:
117
116
118
117
- Open communication with the management machine.
119
118
120
-
- Static IP address assigned; the IP address should be outside the DHCP range but still available on the network segment. This IP address can't be assigned to any other machine on the network.
121
-
- If using DHCP, the control plane IP should be a single reserved IP that is outside of the assignable DHCP range of IPs. No other machine on the network will use or receive this IP from DHCP. DHCP is generally not recommended because a change in IP address (ex: due to an outage) impacts the resource bridge availability.
119
+
- Static IP address assigned and within the IP address prefix.
122
120
123
121
- If using a proxy, the proxy server has to be reachable from IPs within the IP address prefix, including the reserved appliance VM IP.
124
122
@@ -128,23 +126,23 @@ DNS server(s) must have internal and external endpoint resolution. The appliance
128
126
129
127
## Gateway
130
128
131
-
The gateway IP should be an IP from within the subnet designated in the IP address prefix.
129
+
The gateway IP is the IP of the gateway for the network where Arc resource bridge is deployed. The gateway IP should be an IP from within the subnet designated in the IP address prefix.
132
130
133
131
## Example minimum configuration for static IP deployment
134
132
135
-
The following example shows valid configuration values that can be passed during configuration file creation for Arc resource bridge. It is strongly recommended to use static IP addresses when deploying Arc resource bridge.
133
+
The following example shows valid configuration values that can be passed during configuration file creation for Arc resource bridge.
136
134
137
135
Notice that the IP addresses for the gateway, control plane, appliance VM and DNS server (for internal resolution) are within the IP address prefix. This key detail helps ensure successful deployment of the appliance VM.
138
136
139
137
IP Address Prefix (CIDR format): 192.168.0.0/29
140
138
141
-
Gateway (IP format): 192.168.0.1
139
+
Gateway IP: 192.168.0.1
142
140
143
141
VM IP Pool Start (IP format): 192.168.0.2
144
142
145
143
VM IP Pool End (IP format): 192.168.0.3
146
144
147
-
Control Plane IP (IP format): 192.168.0.4
145
+
Control Plane IP: 192.168.0.4
148
146
149
147
DNS servers (IP list format): 192.168.0.1, 10.0.0.5, 10.0.0.6
0 commit comments