Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-209

Periodic continous refresh strategy for ignition server token #364

XMLWordPrintable

    • Periodic continous refresh strategy for ignition server token
    • BU Product Work
    • False
    • False
    • Done
    • OCPSTRAT-326 - Implement HyperShift Infrastructure & Machine Management Models
    • OCPSTRAT-326Implement HyperShift Infrastructure & Machine Management Models
    • 0% To Do, 0% In Progress, 100% Done
    • 0
    • 0
    • 0

      https://github.com/openshift/hypershift/issues/364

      The token should periodically be refreshed on an interval and ultimately old tokens revoked. This provides a secure system overtime and limits the time a exposed secret is active for.

      General idea:

      1. Create new token after some time and use that in userdata secret
      2. After some time has passed (gives enough time for in flight workers to bootstrap) remove old token.

              agarcial@redhat.com Alberto Garcia Lamela
              agarcial@redhat.com Alberto Garcia Lamela
              Jie Zhao Jie Zhao
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: