Uploaded image for project: 'Ansible Automation Platform RFEs'
  1. Ansible Automation Platform RFEs
  2. AAPRFE-168

Add an ability to implement more advanced container registry authentication other than basic one (username & password/token).

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False

      Use-Cases:

      • Accessing Azure Container Registry from AAP using Azure Active Directory (Azure AD) service principal.
        We have our custom execution environments hosted in Azure Container registry and currently they are accessed from the AAP using the "Container Registry" credential type (through the Admin account configured in the registry).
        Our new security policies demands Azure AD based authentication to this Container registry. On the "Container Regi
        stry" Credential type we see only username & password/token fields. Is it possible to access the Azure Container registry from AAP using Azure AD SPN ?
      • How AWS ECR will be used with ansible automation platform as if create registry creds it only gives option for username and password and if we token is getting expired every 12hr
        We are trying to use ECR as registry with AAP but with Execution environment we have only option to use registry credentials which takes only username and password and if we use our service account with AWS which needs a token to be feeded getting expired every 12hr , what is the solution to use AWS ECR with Ansible automation platform with token expiry issue?
      • We are using token files to authenticate to our GCR endpoint. AAP does not have an option under Registry Credentials to use Google Container Registry json files, only username/passwords. Hence, we can not pull our images for Execution Environments
        We can't use our internal container registry to host EE.

              bcoursen@redhat.com Brian Coursen
              rhn-support-snarveka Swati Narvekar
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: