Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-2008

Allow to pre-create shared Tags instead of installer adding it to the pre-created roles for OCP IPI installation on AWS

XMLWordPrintable

    • False
    • False
    • Undefined

      1. Proposed title of this feature request:

       [*] Allow to pre-create shared Tags instead of installer adding it to the pre-created roles for OCP IPI installation on AWS

      2. What is the nature and description of the request?

       [*] From OCP 4.7.11 onwards we can pre-create IAM role for OCP installation on AWS via IPI method, and we can now create a cluster without IAM permission for installer user.
      However, the installer still creates a shared Tag with the pre-created role.

      • Is it possible to skip the permission check for iam:TagRole be removed while create cluster?, and
      • Is it possible to allow pre-creation of those shared Tags instead of the installer adding them?

      3. Why does the customer need this? (List the business requirements here).

       [*] Some customer organisation security team does not allow to give `iam:create` or `iam:tagrole` permissions for the installer user and it is blocked at the organization level.

      That is affecting the deploying of OCP on AWS via IPI method. Since it is allowed to bring your own role, requesting to allow pre-create those shared Tags instead of installer adding it to the pre-created roles during installation.

      4. List any affected packages or components.

      • Installer

            mak.redhat.com Marcos Entenza Garcia
            rh-ee-apjagtap Apoorva Jagtap
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: