-
Feature
-
Resolution: Unresolved
-
Major
-
None
-
Strategic Product Work
-
False
-
-
False
-
OCPSTRAT-1509Tokenized Auth Enablement for OLM-managed Operators on Azure
-
43% To Do, 14% In Progress, 43% Done
-
L
-
0
Feature Overview (aka. Goal Summary)
Increased coverage of layered products and partner offerings supporting standardized Azure Identity configuration flow (OCPBU-560) to support short-lived token authentication on ARO clusters.
Goals (aka. expected user outcomes)
Increase portfolio coverage on ARO with a streamlined, repeatable user experience to ease adoption of the service.
Requirements (aka. Acceptance Criteria):
- based on
OCPBU-560and following OCPBU-564, the following operators will be enabled to support the standard configuration flow for Azure:- 3Scale
- RHODS
- ODF
- ACM
- Quay
- the operators core logic and metadata will be adapted to enable the flow on the command line and the Console outlined here https://docs.google.com/document/d/1iFNpyycby_rOY1wUew-yl3uPWlE00krTgr9XHDZOTNo/edit#heading=h.ih2ff1h4fcfr
Background
For ARO customers these operators represent the larger Red Hat portfolio and integration with Azure Identity is deemed essential for upsell. Having a streamlined process around installing these with integration into Azure Identity tokens will enable security-conscious customers to adopt the platform faster.
Customer Considerations
Customers will have the expectation to use the ccoctl tool to carry out IAM changes in conjunction with ARO. If we are not able to meet it, this needs to be clearly documented and the alternative described in detail.
Documentation Considerations
Every one of these operators needs to clearly outline with IAM permissions are required and provide easy to follow steps to create them. This information should be visible from the operators description (part of the OLM metadata) as well as reside in the components official product documentation.
- is blocked by
-
OCPSTRAT-517 CloudCredentialOperator-based flow for OLM-managed operators and Azure Identity
- Closed
- is related to
-
PROJQUAY-6398 Support the standardized Azure Identity configuration flow via OLM and CCO for Quay
- New