-
Feature
-
Resolution: Won't Do
-
Major
-
None
-
None
-
Strategic Product Work
-
False
-
OCPSTRAT-620OCP reconfiguration
-
0% To Do, 0% In Progress, 100% Done
-
XL
-
0
Feature Overview (aka. Goal Summary)
APIServer auto reconfiguration and certificate generation and rotation when clusterName and baseDomains attributes are updated in the Infrastructure CR as proposed by Feature https://issues.redhat.com/browse/OCPSTRAT-772 (Part 2).
Goals
Enable clusterName and baseDomain reconfiguration as a Day-2 operation
Requirements
- The APIServer should generate certificates for the new name+domain attributes
- The APIServer should start accepting request to with the new identity
- The APIServer should continue handling requests on the previous name+domain for some time to allow rotation and reconfiguration of other components
- The APIServer should continue handling request on the previous name+domain while the admin kubeconfig has not been regenerated
Use Cases & Customer Considerations
Refer to https://issues.redhat.com/browse/OCPSTRAT-620
- blocks
-
OCPSTRAT-775 Auto-reconfigure Kubelet on cluster name or domain change
- Closed
- is blocked by
-
OCPSTRAT-714 Provide Detailed Administrative Control of all OCP Certs and Keys
- In Progress
- is cloned by
-
OCPSTRAT-775 Auto-reconfigure Kubelet on cluster name or domain change
- Closed
-
OCPSTRAT-778 Auto-reconfigure AUTH on cluster name or domain change
- Closed