-
Feature
-
Resolution: Won't Do
-
Major
-
None
-
None
Feature Overview (aka. Goal Summary)
OCP AUTH auto reconfiguration and certificate generation and rotation when clusterName and baseDomains attributes are updated in the Infrastructure CR as proposed by Feature https://issues.redhat.com/browse/OCPSTRAT-772 (Part 2).
Goals
Enable clusterName and baseDomain reconfiguration as a Day-2 operation
Requirements
- OCP Auth should generate certificates for the new name+domain attributes
- OCP Auth should start accepting request to with the new identity
- OCP Auth should continue handling requests on the previous name+domain for some time to allow rotation and reconfiguration of other components
- OCP Auth should continue handling request on the previous name+domain while the admin kubeconfig has not been regenerated
Use Cases & Customer Considerations
Refer to https://issues.redhat.com/browse/OCPSTRAT-620
- blocks
-
OCPSTRAT-775 Auto-reconfigure Kubelet on cluster name or domain change
- Closed
- clones
-
OCPSTRAT-774 Auto-reconfigure APIServer on cluster name or domain change
- Closed
- is blocked by
-
OCPSTRAT-714 Provide Detailed Administrative Control of all OCP Certs and Keys
- In Progress