Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-5428

RHOSP18 Dev Preview Feedback: EDPM shouldn't use passwords in clear text and use a secret to inject registry credentials

XMLWordPrintable

    • Icon: Ticket Ticket
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhos-18.0 Dev Preview 3
    • rhos-dev-preview
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • ?
    • ?
    • ?
    • ?

      Currently in dev preview Compute nodes when login to the container registry use wether edpm_container_registry_logins:

       

      [...]
      apiVersion: dataplane.openstack.org/v1beta1
      kind: OpenStackDataPlaneNodeSet
      metadata:
        name: openstack-edpm-ipam
      spec:
        preProvisioned: True
        ...
        nodeTemplate:
                edpm_podman_buildah_login: true          
                edpm_container_registry_logins:          
                  registry.redhat.io:            
                    testuser: testpassword
      [...] 

      or use edpm_bootstrap_command

       

      apiVersion: dataplane.openstack.org/v1beta1
      kind: OpenStackDataPlaneNodeSet
      metadata:
        name: openstack-edpm-ipam
      spec:
        preProvisioned: True
        ...
        nodeTemplate:
          ansible:
            ...
            ansibleVars:
              edpm_bootstrap_command: |
                subscription-manager register --username <subscription_manager_username> --password <subscription_manager_password>
                subscription-manager release --set=9.2
                subscription-manager repos --disable=*
                subscription-manager repos --enable=rhel-9-for-x86_64-baseos-eus-rpms --enable=rhel-9-for-x86_64-appstream-eus-rpms --enable=rhel-9-for-x86_64-highavailability-eus-rpms --enable=openstack-17.1-for-rhel-9-x86_64-rpms --enable=fast-datapath-for-rhel-9-x86_64-rpms --enable=openstack-dev-preview-for-rhel-9-x86_64-rpms
                podman login -u <registry_username> -p <registry_password> registry.redhat.io 

      Customer require to store passwords in a secret.

       
       

            grosenbe-redhat.com Gil Rosenberg
            pnavarro@redhat.com Pedro Navarro Perez
            rhos-dfg-df
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: