Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-2190

[Dev] Research and document support of TLS Certificates and encryption for control plane services

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Normal Normal
    • rhos-18.0.0
    • None
    • None
    • None
    • 2024Q1

      Jira Description

      As a PCP user I want to encrypt connections to the keystone server so that the data in flight is secure.

       

      Summary

      Having done the research in https://issues.redhat.com/browse/OSP-19150 and https://issues.redhat.com/browse/OSP-19017 , we should be able to determine the architectural components that are needed for certificate provisioning and rotation as well as CRL management. As part of the task, we have to implement cert-manager into openstack-operator and provide guidance on how to use it in individual services.

      Definition of Ready

      When we can consider User Story to be Ready?

      1. Defined clearly enough that all members of the team understand what needs to be done
      2. Includes any required enabling specs. wire frames etc.
      3. Fully meet INVEST criteria for User Stories
      4. Dependencies identified and there is a clear strategy how they will be managed

       

      Prerequisites

      1. Environment with cert-manager created and all of the needed certificate management scenarios reproduced
      2. Environment with IPA created and verified, with cert-manager replacing certmonger

       

      Acceptance Criteria

      1. Documentation created determining the possible architecture of TLS Everywhere in PCP
      2. Initial documentation created for the adoption procedure
      3. Initial documentation on how to use cert-manager in individual services

      Definition of Done

      When we can consider User Story to be Done:

      1. Documentation created for the architecture of TLS Everywhere, consulted with the PCP team (Oliver Walsh etc)
      2. Iniitial documentation created for the adoption procedure, consulted with DPA team (Jiri Stransky)
      3. Initial documentation created on how to secure individual services (for other DFGs)

              rhn-support-mschuppe Martin Schuppert
              hrybacki@redhat.com Harry Rybacki (Inactive)
              rhos-conplat-core-operators
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: