Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-209

Periodic continous refresh strategy for ignition server token #364

XMLWordPrintable

    • Periodic continous refresh strategy for ignition server token
    • False
    • False
    • Done
    • OCPSTRAT-326 - Implement HyperShift Infrastructure & Machine Management Models
    • OCPSTRAT-326Implement HyperShift Infrastructure & Machine Management Models
    • 0% To Do, 0% In Progress, 100% Done
    • 0
    • 0
    • 0

      https://github.com/openshift/hypershift/issues/364

      The token should periodically be refreshed on an interval and ultimately old tokens revoked. This provides a secure system overtime and limits the time a exposed secret is active for.

      General idea:

      1. Create new token after some time and use that in userdata secret
      2. After some time has passed (gives enough time for in flight workers to bootstrap) remove old token.

            agarcial@redhat.com Alberto Garcia Lamela
            agarcial@redhat.com Alberto Garcia Lamela
            Jie Zhao Jie Zhao
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: