Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-59649

Follow up changes for globalPullSecret

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • 4.19.z, 4.20.0
    • HyperShift
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Rejected
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Some requirements were detected during theĀ  globalPullSecret feature implementation, collected here:

      • Investigate to have ephemeral DS to save some resources in DataPlane side (Maybe switching to jobBatch).
      • Small nits in documentation rendered.
      • For security reasons better to mount a volume with the original HCCO and global pullSecrets
      • Try to avoid give permissions to the DS to access API
      • Remove privileged true and reduce the permissions needed
      • Rosa-HCP - in the current implementation, if there is conflicting registry entries, the user entries will take precedence. This would allow the user to potentially override pull secrets set by OCM. The prevent this, the precedence needs to be changed so that on conflict the existing entries take precedence.

              jparrill@redhat.com Juan Manuel Parrilla Madrid
              jparrill@redhat.com Juan Manuel Parrilla Madrid
              None
              None
              Lin Gao Lin Gao
              None
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: