Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-16838

Investigate using spiffe/spire to share workload identity

XMLWordPrintable

    • Product / Portfolio Work
    • 5
    • False
    • Hide

      None

      Show
      None
    • False
    • Hide

      Provide the required acceptance criteria using this template.

      • ...
      Show
      Provide the required acceptance criteria using this template. ...
    • 5
    • SF Train-23, SF Train-25, SF Train-26
    • Moderate
    • None

      Value Statement

      Ensure the issue title clearly reflects the value of this spike story.
      (Explain the "WHY")

       

      We are seeing several scenarios that use a common pattern to access the apiserver of the managed cluster: the service/controller on the hub cluster needs to access the apiserver of the managed cluster.

       

      Spiffe is an open standard to define workload identity, and how a workload can register and get its identity, while spire is an implementation of spiffe. It does not depend on a certain cloud service, but could integrate with cloud such as aws or gcp.

       

      Definition of Done for Engineering Story Owner (Checklist)

      • Provide a prototype of using Spiffe/Spire to implement the hub cluster access the workload on the manged cluster, refer to the doc

      Development Complete

      • The code is complete.
      • Functionality is working.
      • Any required downstream Docker file changes are made.

      Tests Automated

      • [ ] Unit/function tests have been automated and incorporated into the
        build.
      • [ ] 100% automated unit/function test coverage for new or changed APIs.

      Secure Design

      • [ ] Security has been assessed and incorporated into your threat model.

      Multidisciplinary Teams Readiness

      Support Readiness

      • [ ] The must-gather script has been updated.

              jiazhu@redhat.com Jian Zhu
              jiazhu@redhat.com Jian Zhu
              Hui Chen Hui Chen
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: