-
Story
-
Resolution: Done
-
Blocker
-
None
-
None
-
False
-
None
-
False
-
OCPPLAN-5656 - AWS STS - Security Token Service
AWS recommends using regional STS endpoints instead of global. Make sure ccoctl creates secrets with `sts_regional_endpoints` field set to `regional`.
The sample secret data format should be as follows:
[default]
sts_regional_endpoints = regional
role_name = arn:...:role/some-role-name
web_identity_token_file = /path/to/token
slack thread: https://coreos.slack.com/archives/C040MMMG9B8/p1662653229381429
- is depended on by
-
CORS-2356 Deploy disconnected OpenShift cluster with STS on AWS
- Closed
-
CCO-300 Upgrade disconnected/restricted OpenShift cluster with STS on AWS
- Closed
-
OCPBUGS-2882 [release-4.12] Make ccoctl set sts endpoints to regional in AWS credentials secrets
- Closed
- is related to
-
OCPBUGS-1629 Facing issue while configuring egress IP pool in OCP cluster which uses STS
- Closed
-
OCPBUGS-1830 Facing issue while configuring S3 ServiceEndpoint in OCP cluster which uses STS
- Closed
- links to