-
Feature
-
Resolution: Done
-
Critical
-
openshift-4.18, openshift-4.19
-
Product / Portfolio Work
-
-
0% To Do, 0% In Progress, 100% Done
-
False
-
-
False
-
None
-
8
-
None
-
-
None
-
None
-
None
-
None
-
-
None
Feature Overview (aka. Goal Summary)Â Â
In order for Managed OpenShift Hosted Control Planes to run as part of the Azure Redhat OpenShift, it is necessary to support the new AKS design for secrets/identities.
Goals (aka. expected user outcomes)
Hosted Cluster components use the secrets/identities provided/referenced in the Hosted Cluster resources creation.
Requirements (aka. Acceptance Criteria):
All OpenShift Hosted Cluster components running with the appropriate managed or workload identity.
Â
Anyone reviewing this Feature needs to know which deployment configurations that the Feature will apply to (or not) once it's been completed. Describe specific needs (or indicate N/A) for each of the following deployment scenarios. For specific configurations that are out-of-scope for a given release, ensure you provide the OCPSTRAT (for the future to be supported configuration) as well.
Deployment considerations | List applicable specific needs (N/A = not applicable) |
Self-managed, managed, or both | Managed |
Classic (standalone cluster) | No |
Hosted control planes | Yes |
Multi node, Compact (three node), or Single node (SNO), or all | All supported ARO/HCP topologies |
Connected / Restricted Network | All supported ARO/HCP topologies |
Architectures, e.g. x86_x64, ARM (aarch64), IBM Power (ppc64le), and IBM Z (s390x) | All supported ARO/HCP topologies |
Operator compatibility | All core operators |
Backport needed (list applicable versions) | OCP 4.18.z |
UI need (e.g. OpenShift Console, dynamic plugin, OCM) | No |
Other (please specify) | Â |
Background
This is a follow-up to OCPSTRAT-979 required by an AKS sweeping change to how identities need to be handled.
Documentation Considerations
Should only affect ARO/HCP documentation rather than Hosted Control Planes documentation.
Interoperability Considerations
Does not affect ROSA or any of the supported self-managed Hosted Control Planes platforms
- incorporates
-
OCPSTRAT-979 Integrate Azure Workload Identities and Managed Service Identity (MSI) for Operators (control plane/data plane) - Part I
-
- Closed
-
- is related to
-
OCPSTRAT-979 Integrate Azure Workload Identities and Managed Service Identity (MSI) for Operators (control plane/data plane) - Part I
-
- Closed
-
- links to