-
Epic
-
Resolution: Unresolved
-
Critical
-
None
-
None
-
None
-
Create TLS artifacts registry
-
Strategic Product Work
-
13
-
False
-
None
-
False
-
Not Selected
-
In Progress
-
OCPSTRAT-709 - [internal] All OCP internal certificate chains must have clear ownership
-
75% To Do, 0% In Progress, 25% Done
-
XL
In order to keep track of existing certs/CA bundles and ensure that they adhere to requirements we need to have a TLS artifact registry setup.
The registry would:
- have a test which automatically collects existing certs/CA bundles from secrets/configmaps/files on disk
- have a test which collects necessary metedata from them (from cert contents or annotations)
- ensure that new certs match expected metadata and have necessary annotations on when a new cert is added
Ref: API-1622
- incorporates
-
OCPSTRAT-1395 Automated control-plane recovery from expired certificates (hibernation)
- In Progress
- is related to
-
OCPSTRAT-537 Improve API server certificate rotation [API-1579]
- Closed
- links to
(1 links to)