Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-525

Make it possible for HostedCluster users w/o mgmt cluster access to access audit logs

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • None
    • False
    • None
    • False
    • Hypershift Sprint 232
    • 0
    • 0
    • 0

      Currrently, the KAS audit logs are tailed from a sidecar. This allows anyone with access to the mgmt cluster to access them. Often times however, the person who owns the hostedcluster won't be able to access its namespace in the mgmt cluster.

      AC:

      • There are configuration options to setup audit log forwarding on the HostedCluster
      • Possible audit log destination config should be similiar to what the cluster logging operator offers
      • Audit logs arrive when configured

      Related slack discussion: https://coreos.slack.com/archives/C02LM9FABFW/p1658859552470629

            Unassigned Unassigned
            aleman@silpion.de Alvaro Aleman (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: