Uploaded image for project: 'Agent-based Installer for OpenShift'
  1. Agent-based Installer for OpenShift
  2. AGENT-1374

[installer] Create manifests for the registry's root and TLS certificates and its private key

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Duplicate
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None

      Generate manifests for the root certificate, registry TLS certificate, and registry private key.

      The manifests should be generated when the FeatureGate is present and when the IRI resource is detected. But this condition can be added at a later point if needed.

      The certificates are stored in a config map and the private key is stored in a secret.

      Acceptance Criteria:

      • The root certificate is added to the nodes' CA trust store.
      • The TLS certificate and private is made available to deploy the registry service during bootstrap and when a node is installed.

      How the MCS certificates are generated is a useful example to follow. See installer/pkg/asset/manifests/operators.go.

              afasano@redhat.com Andrea Fasano
              rwsu1@redhat.com Richard Su
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: