-
Feature
-
Resolution: Unresolved
-
Major
-
None
-
BU Product Work
-
False
-
-
False
-
OCPSTRAT-1501Tokenized Auth Enablement for OLM-managed Operators on GCP
-
0% To Do, 100% In Progress, 0% Done
-
L
-
0
Feature Overview (aka. Goal Summary)
The following OLM-managed operators are deemed critical and shall be enabled for the standardized GCP configuration flow (OCPSTRAT-922):
- OADP - OADP-4735
- Cluster Logging - Loki Operator -
OBSDA-319and Vector - OBSDA-746 - GCP Filestore CSI operator - STOR-1988
- OpenShift Pipelines -
SRVKP-4400
Goals (aka. expected user outcomes)
Unblock critical functionality on ROSA with a streamlined, repeatable user experience to ease adoption of the service.
Requirements (aka. Acceptance Criteria):
- based on
OCPSTRAT-922, the following operators will be enabled to support the standard configuration flow for GCP WIF:- OADP
- Cluster Logging
- GCP Filestore CSI operator (as applicable)
- OpenShift Pipelines
- the operators core logic and metadata will be adapted to enable the flow on the command line and the Console
Background
In interaction with OSD-GCP customers these operators often come up as foundational to successful adoption of the platform. Having a streamlined process around installing these with integration into GCP WIF will enable security-conscious customers to adopt the platform faster.
Customer Considerations
Customers are trained to use the ccoctl tool to carry out IAM changes in conjunction with OSD GCP.
Documentation Considerations
Every one of these operators needs to clearly outline with IAM permissions are required and provide easy to follow steps to create them. This information should be visible from the operators description (part of the OLM metadata) as well as reside in the components official product documentation.
- depends on
-
STOR-1988 GCP Filestore WIF auth support
- In Progress
-
SRVKP-4400 Add WIF support for tekton results
- Closed
-
SRVKP-6182 Google Storage backend with WIF support in Tekton Cache stepactions
- Closed
-
CCO-585 Check Operator usage
- Closed
-
OBSDA-746 Enable GCP WIF Authentication in Vector
- To Do
-
OCPSTRAT-922 CloudCredentialOperator-based flow for OLM-managed operators and GCP WIF
- Closed
-
OBSDA-319 OpenShift Loki Operator WIF Support Missing.
- Closed
-
OBSDA-527 Enable Grafana support for cloud providers in Loki
- Closed
- relates to
-
OCPSTRAT-1616 Continued GCP WIF enablement for OLM-managed operators
- New
- links to