-
Story
-
Resolution: Done
-
Normal
-
None
-
None
-
None
-
8
-
False
-
-
False
-
?
-
?
-
OSPRH-813 - Red Hat OpenStack 18.0 Data Plane Adoption
-
?
-
?
-
DFG Security: UC Sprint 93, DFG Security: UC Sprint 94
-
2024Q2
The default expected behavior after adopting the data plane would be that the new certificates are generated, uploaded into the EDPM nodes and placed in the right places, but the services running on those nodes are not restarted or notified in any way.
This might be an issue, since the old certificates will not be tracked by the new control plane.
The following might be possible:
- Schedule a planned restart of EDPM nodes, which should happen within a month after the Data Plane Adoption takes place, making sure no certificate expires before this time.
- Trigger certificate reload for all of the EDPM services or apply the certificate reload commands. This should not restart or interrupt any workloads on EDPM
- Upload the old certificates for tracking into the new control plane, so cert-manager can keep track of the old certificates and reload them as needed.
- blocks
-
OSPRH-4086 Test Adoption of existing env to nextgen using TLSe
- Closed
- clones
-
OSPRH-2180 [Dev] Implement support for TLS certificate rotation/provisioning in keystone-operator with IPA
- Closed