Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-14645

[HIVE] uses a long lived token

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Normal Normal
    • ACM 2.13.0
    • ACM 2.12.0
    • Hive
    • False
    • None
    • False
    • Hide

      Provide the required acceptance criteria using this template.
      * ...
      Show
      Provide the required acceptance criteria using this template. * ...
    • None

      Value Statement

      OpenShift has moved away from long lived tokens.  On a default install of MCE, Hive creates a long lived token.

      oc get secrets \
          --all-namespaces \
          --field-selector type=kubernetes.io/service-account-token

      This token either needs to change or be removed.  I don't believe OCP allows for justification.{}

      Definition of Done for Engineering Story Owner (Checklist)

      • The secret query does NOT return a hive secret.

      Development Complete

      • The code is complete.
      • Functionality is working.
      • Any required downstream Docker file changes are made.

      Tests Automated

      • [ ] Unit/function tests have been automated and incorporated into the
        build.
      • [ ] 100% automated unit/function test coverage for new or changed APIs.

      Secure Design

      • [ ] Security has been assessed and incorporated into your threat model.

       

              efried.openshift Eric Fried
              jpacker@redhat.com Joshua Packer
              Mingxia Huang Mingxia Huang
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: