Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-525

Make it possible for HostedCluster users w/o mgmt cluster access to access audit logs

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • None
    • False
    • None
    • False
    • Hypershift Sprint 232
    • 0
    • 0
    • 0

      Currrently, the KAS audit logs are tailed from a sidecar. This allows anyone with access to the mgmt cluster to access them. Often times however, the person who owns the hostedcluster won't be able to access its namespace in the mgmt cluster.

      AC:

      • There are configuration options to setup audit log forwarding on the HostedCluster
      • Possible audit log destination config should be similiar to what the cluster logging operator offers
      • Audit logs arrive when configured

      Related slack discussion: https://coreos.slack.com/archives/C02LM9FABFW/p1658859552470629

              Unassigned Unassigned
              aleman@silpion.de Alvaro Aleman (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: