Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-110

Hypershift-enablement for short-lived token authentication flows with OLM-managed operators with CCO

XMLWordPrintable

    • Strategic Portfolio Work
    • True
    • Hide

      Completion of AWS security audit work.

      Show
      Completion of AWS security audit work.
    • False
    • OCPSTRAT-6Tokenized Auth Enablement for OLM-managed Operators on AWS
    • 0% To Do, 0% In Progress, 100% Done
    • L
    • 0

      Feature Overview:

      Hypershift-provisioned clusters, regardless of the cloud provider support the proposed integration for OLM-managed integration outlined in OCPBU-559 and OCPBU-560.

       

      Goals 

      There is no degradation in capability or coverage of OLM-managed operators support short-lived token authentication on cluster, that are lifecycled via Hypershift.

       

      Requirements:

      • the flows in OCPBU-559 and OCPBU-560 need to work unchanged on Hypershift-managed clusters
      • most likely this means that Hypershift needs to adopt the CloudCredentialOperator
      • all operators enabled as part of OCPBU-563, OCPBU-564, OCPBU-566 and OCPBU-568 need to be able to leverage short-lived authentication on Hypershift-managed clusters without being aware that they are on Hypershift-managed clusters
      • also OCPBU-569 and OCPBU-570 should be achievable on Hypershift-managed clusters

       

      Background

      Currently, Hypershift lacks support for CCO.

      Customer Considerations

      Currently, Hypershift will be limited to deploying clusters in which the cluster core operators are leveraging short-lived token authentication exclusively.

      Documentation Considerations

      If we are successful, no special documentation should be needed for this.

       

              azaalouk Adel Zaalouk
              DanielMesser Daniel Messer
              Daniel Geoffroy (Inactive), James Harrington, Jeremiah Stuever, Jianping Shu, Lance Galletti, Mike Worthington, Steve Kuznetsov (Inactive)
              Jianping Shu Jianping Shu
              Matthew Werner Matthew Werner
              Steve Kuznetsov Steve Kuznetsov (Inactive)
              Senthamilarasu S Senthamilarasu S
              Votes:
              0 Vote for this issue
              Watchers:
              24 Start watching this issue

                Created:
                Updated:
                Resolved: