Uploaded image for project: 'OpenShift Hosted Control Plane'
  1. OpenShift Hosted Control Plane
  2. HOSTEDCP-818

Expose full audit logging configuration in HostedCluster

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • False
    • None
    • False
    • Hypershift Sprint 232
    • 0
    • 0
    • 0

      We currently only expose configuration via OpenShift's config API
      More control is needed to forward logs to customer data plane.

      Expose full configuration of audit logging in KAS via the HostedCluster API

       

      Notes from https://issues.redhat.com/browse/HOSTEDCP-525

      Currrently, the KAS audit logs are tailed from a sidecar. This allows anyone with access to the mgmt cluster to access them. Often times however, the person who owns the hostedcluster won't be able to access its namespace in the mgmt cluster.

      AC:

      • There are configuration options to setup audit log forwarding on the HostedCluster
      • Possible audit log destination config should be similiar to what the cluster logging operator offers
      • Audit logs arrive when configured

      Related slack discussion: https://coreos.slack.com/archives/C02LM9FABFW/p1658859552470629

              imain@redhat.com Ian Main (Inactive)
              cewong@redhat.com Cesar Wong
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: