This is not endorsed or supported in any way by Red Hat, YMMV
Here's a good overview of AWS LB types and what they support
-
Operator requires WAF (Web Application Firewall) in front of their workloads running on OpenShift (ROSA)
-
Operator does not want WAF running on OpenShift to ensure that OCP resources do not experience Denial of Service through handling the WAF
Uses a custom domain, custom route, LE cert. CloudFront and WAF
Installs the ALB Operator, and uses the ALB to route via WAF, one ALB per app though!