Fixing Git clone in air-gapped environment

In air-gapped environments, URLs that start with service-, such as the default Control SSH URL, are not accessible from the dev container terminal. You can replace this URL with the internal cluster-local service address to clone a repository.

Before you begin

You must have the following information:
  • Access to a dev container terminal running in an air-gapped environment.

About this task

In air-gapped environments, URLs that start with service-, for example git@service-loop.loopairgapvpc1.us-east.containers.appdomain.cloud:30328, point to an external endpoint that air-gapped virtual private clouds (VPCs) cannot reach. As a result, you cannot use the default Control SSH URL to clone a repository directly from the dev container terminal.

To work around this restriction, replace the external Control SSH hostname with the internal cluster-local service address before you run git clone.

Procedure

  1. Identify the failing Git command
    1. Locate the git clone command, or any other Git SSH operation, that references the external Control SSH URL.
    2. An example of a URL that fails in an air-gapped environment is shown below:

      git clone ssh://git@service-loop.loopairgapvpc1.us-east.containers.appdomain.cloud:30328/test_ts/.devopsconfig.git

  2. Replace the Control SSH hostname
    1. Replace the hostname portion of the URL with the internal cluster-local service address, using the following format, where platform_namespace is typically devops-loop:

      git@devops-loop-control-ssh.<platform_namespace>.svc.cluster.local:22

    2. Change the port number to (22) and keep the repository path unchanged. Only the hostname and port may be modified.
      Note:
      Do not modify any other part of the URL. The repository path and all other URL components must remain exactly as they are.
  3. Run the updated clone command
    1. In the dev container terminal, run the updated git clone command. For example:

      git clone ssh://git@devops-loop-control-ssh.devops-loop.svc.cluster.local:22/test_ts/.devopsconfig.git

    2. The Control repository clones successfully because the dev container resolves the internal cluster-local address instead of attempting to reach the inaccessible external service- URL.