-
Story
-
Resolution: Done
-
Undefined
-
None
-
None
-
BU Product Work
-
False
-
None
-
False
-
OCPSTRAT-156 - Netobserv operator: Make configuration simpler
-
-
-
-
NetObserv - Sprint 235, NetObserv - Sprint 236, NetObserv - Sprint 237
Based on https://issues.redhat.com/browse/NETOBSERV-684 (certificate watchers), we can implement copying certificates from other namespaces when they are not already in the desired namespace.
It should address two use cases:
- When using Kafka + TLS + eBPF agent, users are currently required to manually copy Kafka certificates in eBPF's privileged namespace
- When Loki, or Kafka, is installed in a different namespace than netobserv', users are required to manually copy their certificates in netobserv namespace
We need to add a new "Namespace" field in TLS certificate config, in FlowCollector, that designate the source namespace where the certificate exists. When not provided, it is assumed to be same as "spec.namespace".
Note that the work was already partially implemented there: https://github.com/netobserv/network-observability-operator/pull/172/ (dependent operators PR) => copying to privileged namespace was done, but done allowing copy from any namespace
- duplicates
-
NETOBSERV-639 Automate kafka secrets copy in eBPF agent privileged namespace
- Closed
- is related to
-
NETOBSERV-1045 When node reboots, Network Observability takes a while before recovering.
- Closed
- links to
- mentioned on