-
Task
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
None
-
None
-
BU Product Work
-
False
-
None
-
False
-
OCPSTRAT-1395 - Automated control-plane recovery from expired certificates (hibernation)
-
-
Instead of a patch for cluster-kube-apiserver-operator custom rotation setting for dev branches it should be product-wide and enabled by a separate FeatureGate. This will ensure that:
- certificates and CAs are short lived on initial install, not just on rotation
- rotation is tested in techpreview jobs
- no longer required to be reverted after branching
Thinks to cover:
- standard IPI install (AWS/GCP)
- hypershift
- SNO with assisted installer
- signer/CA/leaf cert regeneration
- client side cert reloading
- disruption
- correct logging/reporting
- is related to
-
API-1687 Impact cert issues after 4.14 to 4.15 upgrade
- Review
- relates to
-
OCPSTRAT-1797 Hitless TLS Certificate Rotation for Kubernetes API
- New
- links to