Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7121

Handle Post Install Creation of OIDC Client Secrets for HyperShift

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • Hosted Control Planes
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Handle Post Install Creation of OIDC Client Secrets
      2. As part of ARO HCP, if we take customer secret data we need to support encryption at multiple levels. As a result, allowing the customer to configure the console day2 when configuring external OIDC / external AUTH should be possible to get around restrictions of customers passing data to us and us having to support customer-managed keys encryption at rest in all the places it's stored including a k8s secret.
      3. Allows us to adhere to MSFT data handling requirements of Customer Content
      4. HyperShift control plane operator

      See: https://github.com/openshift/hypershift/pull/5351/files and https://docs.google.com/document/d/1_vo4Ayng-vZlCagRgtOvmq69HcgxXOyijO_s3IauX00/edit?tab=t.0 for details.

              racedoro@redhat.com Ramon Acedo
              bvesel.openshift Ben Vesel
              None
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                None
                None