-
Story
-
Resolution: Done
-
Blocker
-
None
-
Strategic Product Work
-
False
-
None
-
False
-
OCPSTRAT-506 - ARO Managed Identity
-
-
Evaluate if any of the Azure predefined roles in the credentials request manifests of OpenShift cluster operators give elevated permissions. Remove any such predefined role from spec.predefinedRoles field and replace it with required permissions in the new spec.permissions field.
Investigation/effort required for following components:
- Cloud Credential Operator
- Cloud Controller Manager Operator
- Machine API Operator
- Cluster CAPI Operator
- Cluster Image Registry Operator
- Cluster Ingress Operator
- Cluster Network Operator
- Cluster Storage Operator
- depends on
-
CCO-294 Update Azure Credentials Request manifest of the Cluster Network Operator to use new API field for requesting permissions
- Closed
-
CCO-299 Update Azure Credentials Request manifest of the Cloud Credentials Operator to use new API field for requesting permissions
- Closed
-
IR-363 Update Azure Credentials Request manifest of the Cluster Image Registry Operator to use new API field for requesting permissions
- Closed
-
NE-1244 Update Azure Credentials Request manifest of the Cluster Ingress Operator to use new API field for requesting permissions
- Closed
-
OCPCLOUD-2014 Update Azure Credentials Request manifest of the Machine API Operator to use new API field for requesting permissions
- Closed
-
OCPCLOUD-2149 Azure: Convert Cloud Controller Manager and Node Manager to use CCO provided credentials instead of system-assigned identity
- Closed
-
STOR-1274 Update Azure Credentials Request manifest of the Cluster Storage Operator to use new API field for requesting permissions
- Closed
-
OCPCLOUD-2013 Update Azure Credentials Request manifest of the Cloud Controller Manager Operator to use new API field for requesting permissions
- Closed
- is depended on by
-
CCO-282 Azure OpenShift role granularity for Azure managed identity
- Release Pending
- relates to
-
OCPCLOUD-2012 Update ARO Credentials Request manifest of the Cluster CAPI Operator to use new API field for requesting permissions
- Closed