Uploaded image for project: 'OpenShift Image Registry'
  1. OpenShift Image Registry
  2. IR-350

Support OpenShift TLSSecurityProfiles via APIServer Config

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • Other
    • None
    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • None

      As a cluster admin I want the image registry to use the APIServer Config CR as the single source of truth for TLS configuration, so that I can ensure the use of modern and secure ciphers.

      Note that the defeault TLS security profile is "Intermediate", which uses TLS 1.2, making these changes backward compatible (all registry operator and operand endpoints currently use TLS 1.2).

      ACCEPTANCE CRITERIA

      • Changes to APIServer TLS profile automatically propagate to cluster-image-registry-operator metrics server (/metrics, in pkg/metrics/server.go)
      • Changes to APIServer TLS profile automatically propagate to image-registry apis (/v2 and /metrics)
      • E2E tests in openshift CI for the above

      TESTING

      DOCS

      • Needs to be mentioned in the release notes
      • Specific documentation for this is not needed, since APIServer Config is what governs this configuration

              rmarasch@redhat.com Ricardo Maraschini
              fmissi Flavian Missi
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: