Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-547

Improve Key Handling and Encryption for Kube API Server

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • OCPSTRAT-714Comprehensive overhaul of handling OCP internal cert & keys
    • 60
    • 60% 60%
    • XL
    • 0
    • 0
    • Program Call

      Feature Overview (aka. Goal Summary)  

      Goals (aka. expected user outcomes)

      • Minimize the impact of encryption keys rotation
      • Investigate the impact of losing the primary encryption key
      • Improve CI job for e2e encryption
      • Test and document how long an encrypted etcd backup can be accessed
      • Investigate hitless updates of encryption configuration for api server
      • Document process for manual forced encryption key rotation
      • Improvements to ancillary dependencies (e.g. go-lang library)

      Requirements (aka. Acceptance Criteria):

      • rotation of encryption keys should be a non-event even for a high cluster with high level of transactions

            wcabanba@redhat.com William Caban
            wcabanba@redhat.com William Caban
            Wei Sun Wei Sun
            Stephanie Stout Stephanie Stout
            Eric Rich Eric Rich
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: