Uploaded image for project: 'OpenShift Image Registry'
  1. OpenShift Image Registry
  2. IR-390

Expose registry CAs as one to MCO

    XMLWordPrintable

Details

    • Task
    • Resolution: Done
    • Undefined
    • openshift-4.14
    • None
    • None
    • None
    • Sprint 238

    Description

      To enable the MCO to replace the node-ca, the registry operator needs to provide its own CAs in isolation.

      Currently, the registry provides its own CAs via the "image-registry-certificates" configmap. This configmap is a merge of the service ca, storage ca, and additionalTrustedCA (from images.config.openshift.io/cluster).

      Because the MCO already has access to additionalTrustedCA, the new secret does not need to contain it.

       

      ACCEPTANCE CRITERIA

      TBD

      Attachments

        Activity

          People

            fmissi Flavian Missi
            fmissi Flavian Missi
            xiujuan wang xiujuan wang
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: