Uploaded image for project: 'Agent-based Installer for OpenShift'
  1. Agent-based Installer for OpenShift
  2. AGENT-1392

InternalReleaseImage registry certificate rotation

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • None
    • openshift-4.21
    • None
    • None
    • InternalReleaseImage certificate rotation
    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • Green
    • In Progress
    • OCPSTRAT-2251 - [GA] Agent Installer for OpenShift Virtualization - Day-1 and Day-2 add a new node w/o an external registry
    • OCPSTRAT-2251[GA] Agent Installer for OpenShift Virtualization - Day-1 and Day-2 add a new node w/o an external registry
    • 75% To Do, 25% In Progress, 0% Done
    • L
    • Hide

      Jan 30, 2026 - Green

      • Analyzing existing MCS certificate rotation process and formulating plan to rotate IRI certificate. As a first step, we need to update IRI controller to recognize certificate changes and update master/worker ignitions. After that, we implement the IRI certificate rotation which will rely on first step as the mechanism to push out certificate changes.
      Show
      Jan 30, 2026 - Green Analyzing existing MCS certificate rotation process and formulating plan to rotate IRI certificate. As a first step, we need to update IRI controller to recognize certificate changes and update master/worker ignitions. After that, we implement the IRI certificate rotation which will rely on first step as the mechanism to push out certificate changes.
    • Critical

      Epic Goal

      • Introduce a mechanism to allow the rotation of the TLS certificate used by the IRI registry

      Why is this important?

      • The certificate generated by the installer when deploying a new cluster for the IRI registry doesn't not get rotated, and this is a requirement for the security concerns.

      Scenarios

      1. ...

      Acceptance Criteria

      • CI - MUST be running successfully with tests automated
      • Release Technical Enablement - Provide necessary release enablement details and documents.
      • ...

      Dependencies (internal and external)

      1. ...

      Previous Work (Optional):

      Open questions::

      Done Checklist

      • CI - CI is running, tests are automated and merged.
      • Release Enablement <link to Feature Enablement Presentation>
      • DEV - Upstream code and tests merged: <link to meaningful PR or GitHub Issue>
      • DEV - Upstream documentation merged: <link to meaningful PR or GitHub Issue>
      • DEV - Downstream build attached to advisory: <link to errata>
      • QE - Test plans in Polarion: <link or reference to Polarion>
      • QE - Automated tests merged: <link or reference to automated tests>
      • DOC - Downstream documentation merged: <link to meaningful PR>

              rwsu1@redhat.com Richard Su
              afasano@redhat.com Andrea Fasano
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: