Uploaded image for project: 'OpenShift Hive'
  1. OpenShift Hive
  2. HIVE-3055

hiveadmission TLS customization for non-OpenShift hub

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None

      There's a push to centralize TLS configuration in preparation for post-quantum cryptography (see OCPSTRAT-2611).

      Today, hiveadmission gets these settings from the pod spec in bindata (source) where they're currently absent. HIVE-3007 added a code path to parlay settings from the APIServer resource to the appropriate CLI settings when running on OpenShift (since APIServer is OpenShift-specific).

      To complete the picture, we need some way of configuring these CLI settings on the hiveadmission pod when we're running on non-OpenShift k8s. Likely one of the following:

      • We can't inherit from APIServer. Is there some other k8s-generic object we can reliably inherit from?
      • Add a knob to e.g. hiveconfig allowing the customer to configure the settings directly.
      • Decide it's not important and close this card.

      I'm linking, but not blocking, HIVE-3007/OCPSTRAT-2611, as those care about OpenShift specifically.

              Unassigned Unassigned
              efried.openshift Eric Fried
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: