Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-56814

Automate PodSecurityConfiguration rendering from the feature gate status

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • 4.20.0
    • 4.20
    • HyperShift
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Several manual PRs have been done in different releases to change the PodSecurityConfiguration, e.g.
      https://github.com/openshift/hypershift/pull/6201/files#diff-3157786f251d6717e0b177770ccf2efff8cf235eeec0f43bca7d5488e543af28R119

      Standalone renders this depending on the gate status https://github.com/openshift/cluster-kube-apiserver-operator/blob/main/pkg/operator/configobservation/auth/podsecurityadmission.go#L67-L71
      HCP should implement the same behaviour.

      This is specially true since 4.19 hcp renders gates on the fly via CCO.

              Unassigned Unassigned
              agarcial@redhat.com Alberto Garcia Lamela
              None
              None
              XiuJuan Wang XiuJuan Wang
              None
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: