Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6536

automatically rotates/"reissues" init-bundles when when RHACS is installed via an operator Description

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • rhacs, rhacs-operator
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

      Automatically Renew the certificates for sensor, admission-control and collector installed through RHACS Operator.

      2. What is the nature and description of the request?

      Didn't find any feature that automatically rotates/"reissues" init-bundles when RHACS is installed via an operator. Only for the specific case of "automatic upgrades":
      "Automatic upgrades are only applicable to static manifest-based deployments using the roxctl CLI. See "Installing Central" in the "Installing by using the roxctl CLI" section of the Installing chapter."

      Source: https://docs.openshift.com/acs/4.4/configuration/reissue-internal-certificates.html#reissue-internal-certificates-secured-clusters-automatic-upgrade_reissue-internal-certificates

      Hence need feature to automatic upgrade the certificates .

      3. Why does the customer need this? (List the business requirements here)

      When the certificates expire we need to manually renew it. And if this window is missed, which is more likely with a manual process, then connection to the secured cluster is lost. The customer has a lot of clusters connected to RHACS and thus wants it to be automatically integrated. RHACS is an integral part of our security posture and is integrated with their SIEM and thus aligns with business goals. Being "blind" for an extended period for the secured clusters due to an issue that should be automated like certificate rotation, needs to be avoided.

      4. List any affected packages or components.

              atelang@redhat.com Anjali Telang
              rhn-support-agawand Asmita Gawand
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: