Uploaded image for project: 'OpenShift Console'
  1. OpenShift Console
  2. CONSOLE-2841

Update console to use a CA file for each cluster

    XMLWordPrintable

Details

    • Console - Sprint 202

    Description

      Remove the use of insecure-skip-verify when connecting to API servers and OAuth servers on managed clusters. The console operator should pass a CA file to the console backend for each spoke cluster.

      Each cluster has a namespace on the hub cluster. The CA file is available from a secret in that namespace. The console operator will need to read those secrets and mount the CA file for each cluster into the console pod.

      Acceptance Criteria

      • We must handle cases where the kubeconfig is missing (for instance because the cluster is still being imported)
      • All use of InsecureSkipVerify is removed from the backend (talking to the API server or OAuth server)

      Attachments

        Activity

          People

            rh-ee-jonjacks Jon Jackson
            spadgett@redhat.com Samuel Padgett
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: