Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-2898

OCP on AWS with manual STS requires private S3 bucket to host OIDC endpoint

XMLWordPrintable

    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request
      OCP on AWS with manual STS requires private S3 bucket to host OIDC endpoint

      2. What is the nature and description of the request?
      Currently, ccoctl creates a public S3 bucket to host OIDC endpoint that is accessible over the internet. Many customers have complained about this approach as their security policies do not allow creation of public S3 bucket.

      3. Why does the customer need this? (List the business requirements here)
      The customer is adopting OCP on AWS and they have very strict security requirements with their Tech Risk teams that block public S3 buckets. They plan to adopt OCP as their Kubernetes of choice for the public cloud (AWS and Google) and thisĀ 

      4. List any affected packages or components.
      This will affect ccoctl and possibly the STS API, and OCP API server

            julim Ju Lim
            rhn-gps-djohnsto David Johnston
            Votes:
            5 Vote for this issue
            Watchers:
            10 Start watching this issue

              Created:
              Updated:
              Resolved: