Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-2860

Admin Ack for SigStore Signature requirements in 4.21

XMLWordPrintable

    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Feature Overview (aka. Goal Summary)  

      An explicit Admin Ack is required to update from 4.20 to 4.21, if the cluster has image mirrors configured (via ICSP or ITMS or ICSP). The cluster admin has to explicitly acknowledge that their registry is capable of storing SigStore signatures (OCI 1.0 compatibility) and that they have used oc-mirror in version 4.21 or newer to mirror the images for 4.21 or newer.

      Goals (aka. expected user outcomes)

      Make customers running disconnected aware that 4.21 will require the SigStore signatures of OpenShift to be present (per OCPSTRAT-2471). This will make them know in advance that they need to use an OCI-compatible registry for their image mirror and use the oc-mirror version aligned with the OpenShift 4.21 release to automatically mirror the OpenShift 4.21 payload, to ensure it also captures the signatures.

      Requirements (aka. Acceptance Criteria):

      • present the admin ack if the cluster is configured with mirrors for quay.io/openshift-release-dev/ocp-release or quay.io/openshift-release-dev/ocp-v4.0-art-dev (or quay.io/openshift-release-dev/)

       

      Anyone reviewing this Feature needs to know which deployment configurations that the Feature will apply to (or not) once it's been completed.  Describe specific needs (or indicate N/A) for each of the following deployment scenarios. For specific configurations that are out-of-scope for a given release, ensure you provide the OCPSTRAT (for the future to be supported configuration) as well.

      Deployment considerations List applicable specific needs (N/A = not applicable)
      Self-managed, managed, or both self-managed
      Classic (standalone cluster) yes
      Hosted control planes yes
      Multi node, Compact (three node), or Single node (SNO), or all all
      Connected / Restricted Network restricted
      Architectures, e.g. x86_x64, ARM (aarch64), IBM Power (ppc64le), and IBM Z (s390x) all
      Operator compatibility n/a
      Backport needed (list applicable versions) n/a
      UI need (e.g. OpenShift Console, dynamic plugin, OCM) none
      Other (please specify)  

       

              trking W. Trevor King
              DanielMesser Daniel Messer
              None
              None
              W. Trevor King W. Trevor King
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: