Uploaded image for project: 'OpenShift API Server'
  1. OpenShift API Server
  2. API-1845

Integrate various apiservers with KMS plugin

XMLWordPrintable

    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • 8
    • None
    • None
    • OAPE Sprint 263, OAPE Sprint 265, OAPE Sprint 267, CBOR/KMS Sprint 5, CBOR/KMS Sprint 6
    • None

      The APIServer Encryption configuration is the single point of entry for configuring KMS encryption.

      OpenShift will manage the KMS plugin on behalf of the user on both releases, TP and GA.

      At the moment of writing, the KMS plugin will be deployed as a static pod. The various openshift apiservers will either:

      1. Each deploy their own kms plugin static pod
      2. Share the socket for the one kms plugin static pod (the approach taken in the PRs linked to this ticket)

      We'll probably go with 1.

              dgrisonn@redhat.com Damien Grisonnet
              dgrisonn@redhat.com Damien Grisonnet
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: