-
Story
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
2
-
False
-
None
-
False
-
-
-
CLOUD Ready for Development
User Story
As a [user|developer|<other>] I want to be able to see what node is requesting an invalid CSR in the logs, without having to request full CSR YAML dumps
Background
We want to make sure we log more information about the CSRs that are coming in when we do not approve them.
For example we should log information about who requested the CSR and the contents of it.
We should not log information about the decision tree, as this would allow a brute force attack.
Steps
- <Add steps to complete this card if appropriate>
Stakeholders
- Cluster Infra
- Trevor
Definition of Done
- <Add items that need to be completed for this card>
- Docs
- <Add docs requirements for this card>
- Testing
- <Explain testing that will be added>
- is triggered by
-
OCPBUGS-8349 Bootstrap kubelet client cert should include system:serviceaccounts group
- Closed
- relates to
-
OCPCLOUD-1105 Re-evaluate CSR approver logging
- To Do