Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-4987

Configure CA trust in MicroShift

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • microshift
    • None
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

      Configure the CA trust for MicroShift through the MicroShift component.
      Either through the MicroShift config file or through the ConfigMap.

      Option A
      In the config file `/etc/microshift/config.yaml` as additionalCertificateAuthorityBundle which will point to the file on the filesystem on the disk.
      Ability to add the bundle in the rpmostree embedded version.

      Option B
      Create a configmap in the "default" or "kube-system" project with specific name or specific annotation, and the microshift service will mount the file to every component including the systemd service.

      2. What is the nature and description of the request?

      Currently the CA can be configured for MicroShift wide through the CA trust of the RHEL system. If customer needs to update that file, they would need to in RPM version to manually upload the file and run "update-ca-trust", or in the Ostree version implement that in the new image.

      3. Why does the customer need this? (List the business requirements here)

      Ability to add custom trust through the MicroShift objects and not through the RHEL.

      4. List any affected packages or components.

      ca trust
      microshift

              dfroehli42rh Daniel Fröhlich
              rhn-support-vwalek Vladislav Walek
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: