-
Story
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
False
-
None
-
False
As an administrator of a cluster utilizing AWS STS with a public S3 bucket OIDC provider, I would like a documented procedure with steps that can be followed to migrate to a private S3 bucket with CloudFront Distribution so that I do not have to recreate my cluster.
ccoctl documentation including parameter `--create-private-s3-bucket`: https://github.com/openshift/cloud-credential-operator/blob/a8ee8a426d38cca3f7339ecd0eac88f922b6d5a0/docs/ccoctl.md
Existing manual procedure for configuring private S3 bucket with CloudFront Distribution: https://github.com/openshift/cloud-credential-operator/blob/master/docs/sts-private-bucket.md
- is cloned by
-
SPLAT-950 [aws][cco] STS Implement procedure for migrating from a public s3 bucket OIDC to a private s3 bucket OIDC with CloudFront Distribution
- Closed
- is related to
-
CCO-219 Explore the option of creating private S3 bucket to host OIDC endpoint
- Closed
-
RFE-3614 Define custom domain in CloudFront to host OIDC public URL
- Under Review
-
CCO-221 Document restricting access to OIDC S3 for STS installations using AWS CloudFront
- Closed
-
CCO-222 Add ccoctl option to create private s3 bucket with OIDC configurations served through public CloudFront URL
- Closed
- relates to
-
RFE-2898 OCP on AWS with manual STS requires private S3 bucket to host OIDC endpoint
- Accepted
- links to