-
Bug
-
Resolution: Done
-
Major
-
None
-
4.19.0
-
Quality / Stability / Reliability
-
False
-
-
None
-
None
-
None
-
None
-
None
-
Rejected
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
https://issues.redhat.com/browse/OCPBUGS-48557 and https://issues.redhat.com/browse/OCPBUGS-46024 were about in-memory certificate which is not stored in secret or on disk. We should find a way to identify such secrets and ensure that they are generated by the operator and saved in the secrets, so that they would appear on TLS registry and we could rotate them effortlessly
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
1. 2. 3.
Actual results:
Expected results:
Additional info:
- is related to
-
OCPBUGS-55335 LoopbackClientConfig is required when creating apiserver
-
- New
-
-
OCPBUGS-61759 In-memory certificate expiration date in openshift-apiserver namespace is too short for ELS term 2
-
- New
-
-
OCPBUGS-61760 In-memory certificate expiration date in oauth-apiserver namespace is too short for ELS term 2
-
- New
-
-
OCPBUGS-54208 Backport UPSTREAM: 130047: adjusting loopback certificate validity in kube-apiserver
-
- Verified
-
- links to