Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-1160

Install image registry CA through MCO

    XMLWordPrintable

Details

    • Story
    • Resolution: Unresolved
    • Normal
    • None
    • None
    • None
    • None
    • False
    • None
    • False
    • 0
    • 0
    • 0

    Description

      The image registry node-ca daemonset is going away. We need to instead lay down its CA using the MCO. 

      Because in HyperShift we only run the MCO in bootstrap mode, we will need to pass the image registry CA to the MCO when generating the ignition payload. That will be made possible by this PR: https://github.com/openshift/machine-config-operator/pull/3876 

      Note: In order to generate the CA for the image registry, we will need to move the service-ca operator to the control plane side.

      Acceptance Criteria:

      Image registry is functional on a hypershift cluster without the node-ca daemonset

      (optional) Out of Scope:

      Detail about what is specifically not being delivered in the story

      Engineering Details:

      This requires/does not require a design proposal.
      This requires/does not require a feature gate.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              cewong@redhat.com Cesar Wong
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated: