-
Feature Request
-
Resolution: Done
-
Normal
-
None
-
openshift-4.12
-
None
-
False
-
None
-
False
-
Not Selected
-
-
1. Proposed title of this feature request
Enable WIF support for pulling images in OpenShift running on Google Cloud Platform (GCP)
2. What is the nature and description of the request?
Enable Workload identity federation support for OpenShift in GCP when pulling from Google Artifact Registry
3. Why does the customer need this? (List the business requirements here)
Per customers organization policy they need to leverage zero trust capabilities of GCP were available, not being able to use WIF would force the customer to create a GCP service accounts keys, and/or HMAC keys, thus they are blocked from fully adopting OpenShift
4. List any affected packages or components.
RHCOS , Kubelet, Cloud integration
https://cloud.google.com/iam/docs/workload-identity-federation
https://docs.openshift.com/container-platform/4.10/authentication/understanding-identity-provider.html
- is triggered by
-
CCO-114 Support GCP workload identity
- Closed