Uploaded image for project: 'Machine Config Operator'
  1. Machine Config Operator
  2. MCO-128

Investigate the use of kube-rbac-proxy vs oauth-proxy for securing metrics endpoints

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • 0

      When I was working on MCO-74, it came up that kube-rbac-proxy may be better to use than oauth-proxy because it conveys some benefits (one of which is that it is easier on the API server).

      This is the referenced enhancement:

      https://github.com/openshift/enhancements/blob/master/enhancements/monitoring/client-cert-scraping.md

      Since both machine-config-daemon and machine-config-controller both use oauth-proxy, if it makes sense and we understand the tradeoffs/consequences we should probably update both of them.

      Done Criteria:

      • We know whether or not we should use kube-rbac-proxy
      • We have updated (or decided not to update) the controller and the daemon to use (or not use) it

       

              Unassigned Unassigned
              jkyros@redhat.com John Kyros
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: