Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-25342

HyperShift should encrypt the same resources that OCP standalone encrypts in etcd

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Critical Critical
    • 4.16.0
    • 4.14
    • HyperShift
    • Critical
    • No
    • Hypershift Sprint 246, Hypershift Sprint 247
    • 2
    • False
    • Hide

      None

      Show
      None

      Description of problem:

          Standalone OCP encrypts various resources at rest in etcd:
      https://docs.openshift.com/container-platform/4.14/security/encrypting-etcd.html
      HyperShift control planes are only encrypting secrets. We should have parity with standalone.

      Version-Release number of selected component (if applicable):

          4.14

      How reproducible:

          Always

      Steps to Reproduce:

          1. Create HyperShift standalone control plane
          2. Check that configmaps, routes, oauth access tokens or oauth authorize tokens are encrypted
          

      Actual results:

          Those resources are not encrypted

      Expected results:

          Those resources are encrypted

      Additional info:

      Resources to be encrypted are configured here:
      https://github.com/openshift/hypershift/blob/main/control-plane-operator/controllers/hostedcontrolplane/kas/kms/aws.go#L121-L126    

              imain@redhat.com Ian Main (Inactive)
              cewong@redhat.com Cesar Wong
              Jie Zhao Jie Zhao
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: