Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-1797

Hitless TLS Certificate Rotation for Kubernetes API

XMLWordPrintable

    • BU Product Work
    • False
    • Hide

      None

      Show
      None
    • False
    • 100% To Do, 0% In Progress, 0% Done
    • 0

      Feature Overview 

      OpenShift relies on internal certificates for communication between components, with automatic rotations ensuring security. For critical components like the API server, rotations occur via a rollout process, replacing certificates one instance at a time.

      In clusters with high transaction rates and SNO, this can lead to transient errors for in-flight transactions during the transition.

      This feature ensures seamless TLS certificate rotations in OpenShift, eliminating downtime for the Kubernetes API server during certificate updates, even under heavy loads or in SNO deployments.

              racedoro@redhat.com Ramon Acedo
              racedoro@redhat.com Ramon Acedo
              Vadim Rutkovsky Vadim Rutkovsky
              Ramon Acedo Ramon Acedo
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: