Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-7022

Certmonger removal prevents control plane adoption rollback

XMLWordPrintable

    • 2
    • False
    • Hide

      None

      Show
      None
    • False
    • ?
    • ?
    • ?
    • ?
    • Hide

      RHOSO18Beta waived:Upgrade: Adoption

      Show
      RHOSO18Beta waived: Upgrade: Adoption
    • DFG Security: UC Sprint 96, DFG Security: UC Sprint 97
    • Critical

      Currently certmonger removal from data plane is documented as a step very early in the adoption procedure. Step 8 here:

      https://openstack-k8s-operators.github.io/data-plane-adoption/user/#migrating-tls-everywhere_storage-requirements

      The issue with this is that it prevents control plane rollback – once we change the data plane, it is considered to be the point of no return.

      From discussion with Grzegorz, this could be moved later in the procedure to the point of adopting data plane. It was placed in the TLS doc to have it together with the rest of the TLS steps (to avoid another "if TLS" section in another doc), but technically it can be done later.

            ggrasza@redhat.com Grzegorz Grasza
            jstransk@redhat.com Jiri Stransky
            rhos-dfg-security
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: