-
Epic
-
Resolution: Done
-
Major
-
None
-
[Spike] Support migration to Azure Managed Identity
-
BU Product Work
-
False
-
None
-
False
-
Not Selected
-
To Do
-
OCPSTRAT-1185 - In-place migration to Microsoft Entra Workload ID for self-managed OpenShift on Azure
-
OCPSTRAT-1185 In-place migration to Microsoft Entra Workload ID for self-managed OpenShift on Azure
-
0% To Do, 0% In Progress, 100% Done
-
Goal
Spike to evaluate if we can provide an automated way to support migration to Azure Managed Identity (preferred), or alternatively a manual method (second option) for customers to perform the migration themselves that is documented and supported, or not at all.
This spike will evaluate, scope the level of effort (sizing), and make recommendation on next steps.
Feature request
Support migration to Azure Managed Identity
Feature description
Many customers would like to migrate to Azure Managed Identity but have numerous existing clusters and an aversion to supporting two concurrent operational requirements. Therefore they would like to migrate existing Azure clusters to Managed Identity in a safe manner after they have been upgraded to a version of OCP supporting that feature (4.14+).
Why?
Provide a uniform operational experience for all clusters running versions which support Azure Managed Identity without having to decommission long running clusters
Other considerations
- Disruption to customer's workload.
- Has to be closely coordinated with update effort to minimize disruption.
- Tokenized operators and other layered products - work not yet done (OCP 4.15/4.16 plans) and has to be manually done for now and may not cover the full set.
- If we grant this for Azure MI/WI, we will likely will need to also do this for STS and GCP WIF.
- If we grant this, would we do this for self-managed and managed OpenShift (ARO)?
- is blocked by
-
OCPBUGS-32948 Azure pod identity webhook not provided after migration to Microsoft Entra Workload ID.
- Closed
-
OCPBUGS-33621 [Migrate to Microsoft Entra Workload ID] An uninitialized variable was used as a string constant during the extraction of the cluster's release image.
- Closed
- is related to
-
OCPSTRAT-1231 Enable Azure managed identity with Azure AD workload identity for self-managed OpenShift for Microsoft Azure Government regions
- New
-
OCPSTRAT-1232 Enable Azure managed identity with Azure AD workload identity for self-managed OpenShift for Azure Stack Hub
- New
-
OCPSTRAT-506 ARO Managed Identity
- Closed
-
OCPSTRAT-513 Azure managed identity with Azure AD workload identity for self-managed OpenShift
- Closed
- is triggered by
-
RFE-4831 Support migration to Azure Managed Identity
- Accepted
- links to