Uploaded image for project: 'Network Observability'
  1. Network Observability
  2. NETOBSERV-773

Copy certificates across namespaces

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • netobserv-1.3
    • None
    • None
    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • NetObserv - Sprint 235, NetObserv - Sprint 236, NetObserv - Sprint 237

      Based on https://issues.redhat.com/browse/NETOBSERV-684 (certificate watchers), we can implement copying certificates from other namespaces when they are not already in the desired namespace.

      It should address two use cases:

      • When using Kafka + TLS + eBPF agent, users are currently required to manually copy Kafka certificates in eBPF's privileged namespace
      • When Loki, or Kafka, is installed in a different namespace than netobserv', users are required to manually copy their certificates in netobserv namespace

      We need to add a new "Namespace" field in TLS certificate config, in FlowCollector, that designate the source namespace where the certificate exists. When not provided, it is assumed to be same as "spec.namespace".

      Note that the work was already partially implemented there: https://github.com/netobserv/network-observability-operator/pull/172/ (dependent operators PR) => copying to privileged namespace was done, but done allowing copy from any namespace

              jtakvori Joel Takvorian
              jtakvori Joel Takvorian
              None
              None
              Mehul Modi Mehul Modi
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: