Uploaded image for project: 'Red Hat Advanced Cluster Security'
  1. Red Hat Advanced Cluster Security
  2. ROX-32803

Cluster Registration Secret (CRS) General Availability

    • Icon: Feature Feature
    • Resolution: Unresolved
    • Icon: Critical Critical
    • 4.10.0
    • None
    • Documentation
    • False
    • Hide

      None

      Show
      None
    • False
    • Green
    • Hide
      In 4.10, we are excited to announce general availability of Cluster Registration Secret(CRS) as a means to securely bootstrap Secured cluster registration with RHACS Central. Unlike the previous initBundle functionality, CRS provides clear separation of credentials used for bootstrapping registration of Secured cluster components from the workflow of internal communication between these components. Users of initBundle should see similar UX as before while registering clusters. Existing clusters that have used initBundle for registeration are not impacted and we recommend using CRS for new cluster registrations only.
      Refer to documentation on how to create CRS for additional information.
      Show
      In 4.10, we are excited to announce general availability of Cluster Registration Secret(CRS) as a means to securely bootstrap Secured cluster registration with RHACS Central. Unlike the previous initBundle functionality, CRS provides clear separation of credentials used for bootstrapping registration of Secured cluster components from the workflow of internal communication between these components. Users of initBundle should see similar UX as before while registering clusters. Existing clusters that have used initBundle for registeration are not impacted and we recommend using CRS for new cluster registrations only. Refer to documentation on how to create CRS for additional information.
    • Yes

      Goal Summary:

      In 4.7 we introduced Cluster Registration Secret(CRS) as a means to securely bootstrap Secured cluster registration with RHACS Central. Unlike the previous initBundle functionality, CRS provides clear separation of credentials used for bootstraping registration of Secured cluster components from the workflow of internal communication between these components. 

      With support in UI as well as CLI, and having reviewed usage in last 3 releases, we are now ready to make this feature Generally available. We are looking to make CRS the default method for registration of Secured cluster and we look to deprecate initBundle usage in a future release. 

      Goals and expected user outcomes:

      Make CRS the recommended choice for secured cluster registration via UI. 

      Remove any TechPreview verbiage 

      Provide deprecation notice for initBundle

      Acceptance Criteria:

      UI clearly shows CRS as recommended way to register Secured clusters with Central

      Customers attempting to register/add new Secured clusters into Central can use CRS without any problem

      In case of upgrades, Clusters that are already registered with initBundle dont have any impact and only for new clusters are recommended to connect using CRS

       

      Success Criteria or KPIs measured:

      Use of CRS as default method for adding Secured clusters

      No disruption to existing clusters added with initBundle

      Use Cases (Optional):

      Include use case diagrams, main success scenarios, alternative flow scenarios together with user type/persona. Initial completion during Refinement status.

      <your text here>

      Out of Scope (Optional):

      High-level list of items that are out of scope. Initial completion during Refinement status.

      <your text here>

              kcarmich@redhat.com Kerry Carmichael
              atelang@redhat.com Anjali Telang
              Kerry Carmichael, Mansur Syed, Mark Pedrotti, Michael Hess, Moritz Clasmeier, Vlad Bologa
              ACS Docs
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: