Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-25342

HyperShift should encrypt the same resources that OCP standalone encrypts in etcd

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Critical
    • 4.16.0
    • 4.14
    • HyperShift
    • Critical
    • No
    • Hypershift Sprint 246, Hypershift Sprint 247
    • 2
    • False
    • Hide

      None

      Show
      None

    Description

      Description of problem:

          Standalone OCP encrypts various resources at rest in etcd:
      https://docs.openshift.com/container-platform/4.14/security/encrypting-etcd.html
      HyperShift control planes are only encrypting secrets. We should have parity with standalone.

      Version-Release number of selected component (if applicable):

          4.14

      How reproducible:

          Always

      Steps to Reproduce:

          1. Create HyperShift standalone control plane
          2. Check that configmaps, routes, oauth access tokens or oauth authorize tokens are encrypted
          

      Actual results:

          Those resources are not encrypted

      Expected results:

          Those resources are encrypted

      Additional info:

      Resources to be encrypted are configured here:
      https://github.com/openshift/hypershift/blob/main/control-plane-operator/controllers/hostedcontrolplane/kas/kms/aws.go#L121-L126    

      Attachments

        Activity

          People

            imain@redhat.com Ian Main
            cewong@redhat.com Cesar Wong
            Jie Zhao Jie Zhao
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

            Dates

              Created:
              Updated: