-
Feature Request
-
Resolution: Won't Do
-
Blocker
-
None
-
None
-
None
-
Product / Portfolio Work
-
None
-
False
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Currently OpenShift only supports an OAuth endpoint and not OIDC however many products have standardized on OIDC. Since OpenShift does not have an OIDC endpoint it means that various Red Hat products (CodeReady Workspaces, GitOps operator, ACS and Quay for example) deployed on top of OpenShift need to use RH-SSO to integrate with OpenShift authentication.
While RH-SSO is a great product, it adds considerable complexity to the ecosystem particularly for customers that would not use it otherwise. Additionally each product owner is providing their own ways to integrate with SSO including standing up a product specific instance of SSO or different ways of configuring realms. This leads to duplication in engineering effort and in cases where customers stand-up SSO independently for each deployed SSO proliferation,
If OpenShift supported an OIDC endpoint (i.e. by adding Dex to the product as a supported operator or natively) this complexity would be elimninated and greatly reduce the burden on customers.
Note I do not have a customer for this RFE, I was specifically asked by Tushar and Katherine to open an RFE for it on the 4.8 What's New call so here it is.