Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-1782

OpenShift integration with external secret managers (Vault)

XMLWordPrintable

    • Icon: Outcome Outcome
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • 62% To Do, 23% In Progress, 15% Done
    • False
    • Hide

      None

      Show
      None

      Outcome Overview

      OpenShift core and layered products make use of keys, credentials, tokens and certificates for many use-cases. Most customers rely on external secret managers such as Vault and public cloud KMS providers to in order to securely manage these sensitive data. The goal of this outcome is enable customers to use external secret managers when providing keys, credentials, certificates and other sensitive data require by OpenShift core and layered operators.

      Success Criteria

      Keys, credentials and certificates used by OpenShift core and layered operators could be provided through external secret managers such as Vault and public cloud KMS providers. These sensitive data includes

      • Support Kube KMS API for encrypting etcd keys
      • Support Secret Store CSI (SSCSI) Driver
      • Support External Secrets Operator (ESO)
      • Support cert-manager
      • Core and layered products to rely on SSSCI Driver, ESO and cert-manager for user-provided sensitive dat
      • SPIFFE/SPIRE integration with Vault

      Expected Results (what, how, when)

      • Enable use of OpenShift with external secret managers
      • Increase the number of OpenShift customers that use IBM Vault
         

      Post Completion Review – Actual Results

      TBD

       

              rh-ee-ssadeghi Siamak Sadeghianfar
              rh-ee-ssadeghi Siamak Sadeghianfar
              Anjali Telang, Ju Lim, Nick Png, Ramon Acedo
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: