-
Epic
-
Resolution: Won't Do
-
Major
-
None
-
openshift-4.10
-
Add image registry for GCP workload identity
-
False
-
None
-
False
-
Not Selected
-
To Do
-
OCPSTRAT-469 - Install and upgrade OpenShift with GCP Workload Identity
-
OCPSTRAT-469Install and upgrade OpenShift with GCP Workload Identity
In OpenShift 4.10.3-4.10.7, GCP Workload Identity works with Image Registry, but Image Registry has known regressions in Bugs2069807 and 2065689.
In OpenShift 4.10.8, image registry support for using GCP Workload Identity was removed due to the discovery of an adverse impact to the image registry (Bugs2069807 and 2065689).
To use the image registry on an OpenShift Container Platform 4.10.8+ cluster that uses GCP Workload Identity, you must configure the image registry to use long-lived credentials instead.
Refer to https://docs.openshift.com/container-platform/4.10/authentication/managing_cloud_provider_credentials/cco-mode-gcp-workload-identity.html and https://access.redhat.com/articles/6898641 for more information.
This epic is intended to track the future work needed to restore Workload Identity support for the image registry in a later release.