Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-5882

TLS everywhere in Horizon operator

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Done-Errata
    • Icon: Blocker Blocker
    • rhos-18.0.0
    • rhos-18.0.0
    • horizon-operator
    • None
    • TLS Everywhere in the horizon operator
    • 5
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • Committed
    • No Docs Impact
    • To Do
    • RHOSSTRAT-282 - TLS-everywhere
    • horizon-operator-bundle-container-1.0.0-15
    • Committed
    • Committed
    • 0% To Do, 0% In Progress, 100% Done
    • Hide
      .TLS everywhere in RHOSO Dashboard Operator

      With this update, the RHOSO Dashboard (horizon) Operator automatically configures TLS-related configuration settings.

      These settings include certificates and response headers when appropriate, including the secure cookies and HSTS headers for serving over HTTPS.
      Show
      .TLS everywhere in RHOSO Dashboard Operator With this update, the RHOSO Dashboard (horizon) Operator automatically configures TLS-related configuration settings. These settings include certificates and response headers when appropriate, including the secure cookies and HSTS headers for serving over HTTPS.
    • Enhancement
    • Done
    • Regression Only
    • 5
    • Approved

      Definition of Done (for development)

      • By implementing <configuration>, a RHOSO 18 deployment is stood up with Horizon correctly configured to provide client-side TLS connectivity, and connect to the back-end via TLS
      • On the client side, all the response headers are configured for maximum security, while still allowing the application to run correctly.
      • Patches proposed and merged into horizon-operator (not necessarily into openstack-operator)
      • Tests developed and implemented to validate the presence of the headers

      Acceptance Criteria (for validation)

      • Horizon delivers content via HTTPS, with secure headers
      • Horizon interacts with OpenStack via HTTPS
      • Integration tests pass

              rhn-engineering-rdopiera Radomir Dopieralski
              rhn-engineering-rdopiera Radomir Dopieralski
              Jan Jasek Jan Jasek
              rhos-dfg-ui
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: