Uploaded image for project: 'OpenShift Top Level Product Strategy'
  1. OpenShift Top Level Product Strategy
  2. OCPPLAN-6006

Apply user defined tags to all AWS resources created by OpenShift

    XMLWordPrintable

Details

    • False
    • False
    • Not Set
    • No
    • Not Set
    • Not Set
    • Not Set
    • 100
    • 100% 100%
    • Undefined

    Description

      Feature Overview

      Apply user defined tags to all resources created by OpenShift in AWS. The OpenShift installer and other components in AWS need to apply the user defined tags to all resources they create in AWS. This is for our customers' admins, compliance and security teams to keep track of assets and objects created by OpenShift (installer and other system components). 

      Requirements

      Scoped for delivery in 4.8:

      User defined tags defined in the install-config.yaml of the IPI installer are tagged to the following AWS components:

      • Classic load balancers, associated with the default ingress controller
      • S3 bucket for internal image registry storage
      • EBS volumes created from a storage class via the CSI driver, (PV/PVC)

      Out of Scope (for 4.8) 

      User defined tags for:

      • Any other ingress controller of type Load Balancing created after install on day 2.
      • EBS volumes and S3 bucket created by OCS
      • Also out of scope is tags in a configmap so that they can be updated after installation.
      • AWS Route 53 records are out of scope 
      • EBS volumes created from a storage class via the in-tree storage driver is out of scope. 

      Cloud Credential Operator minted IAM users are out of scope. CCO in STS mode is not creating IAM users, and the replacement IAM Roles are created by the customer and can be restricted by tag as they wish, within the limits of AWS API capabilities.

      Assumptions

      • Is there source material that can be used as reference for the Technical Writer in writing the content? If yes, please link if available.
      • What is the doc impact (New Content, Updates to existing content, or Release Note)?

      Attachments

        Issue Links

          Activity

            People

              mak.redhat.com Marcos Entenza Garcia
              tkatarki@redhat.com Tushar Katarki
              Votes:
              6 Vote for this issue
              Watchers:
              33 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: