Uploaded image for project: 'OpenShift Cloud Credential Operator'
  1. OpenShift Cloud Credential Operator
  2. CCO-172

Migrate away from Azure AD Graph API dependency

XMLWordPrintable

    • Deprecation of Azure AD Graph API
    • False
    • False
    • Done
    • 0% To Do, 0% In Progress, 100% Done

      Currently, OpenShift (the openshift-installer during cluster destroy and cloud-credential-operator when running in Mint mode) uses the Azure Active Directory Graph API for creating/updating/deleting App Registrations and Service Principals.

      In June 2022, that API is going away https://techcommunity.microsoft.com/t5/azure-active-directory-identity/update-your-applications-to-use-microsoft-authentication-library/ba-p/1257363

      The replacement Microsoft Graph API does not presently have a production-ready Golang SDK (https://docs.microsoft.com/en-us/graph/sdks/create-client?tabs=Go ). Need to migrate off of using the old Azure AD Graph API so that clusters don't enter a degraded state.

            Unassigned Unassigned
            jdiaz@redhat.com Joel Diaz (Inactive)
            Lin Wang Lin Wang
            Votes:
            0 Vote for this issue
            Watchers:
            12 Start watching this issue

              Created:
              Updated:
              Resolved: