Uploaded image for project: 'Knative Serving'
  1. Knative Serving
  2. SRVKS-947

[DOC] Document how users can utilize secret filtering for Net-Kourier

XMLWordPrintable

    • 5
    • False
    • True
    • Hide
      In 1.28 the annotation `serverless.openshift.io/enable-secret-informer-filtering` on the Serving CR is deprecated.
      The annotation is not valid for Kourier, it is only used for Istio.
      In 1.28 Serverless operator allows injecting the env var ENABLE_SECRET_INFORMER_FILTERING_BY_CERT_UID for both net-istio and net-kourier.
      In future releases Serverless operator will enable secret filtering via env var injection by default for both Kourier and Istio.
      Users MUST start annotating their secrets with networking.internal.knative.dev/certificate-uid:some_cuid so they don’t face issues when they upgrade from 1.28 to some future release.
      Show
      In 1.28 the annotation `serverless.openshift.io/enable-secret-informer-filtering` on the Serving CR is deprecated. The annotation is not valid for Kourier, it is only used for Istio. In 1.28 Serverless operator allows injecting the env var ENABLE_SECRET_INFORMER_FILTERING_BY_CERT_UID for both net-istio and net-kourier. In future releases Serverless operator will enable secret filtering via env var injection by default for both Kourier and Istio. Users MUST start annotating their secrets with networking.internal.knative.dev/certificate-uid:some_cuid so they don’t face issues when they upgrade from 1.28 to some future release.

            msvistun@redhat.com Maxim Svistunov
            skontopo@redhat.com Stavros Kontopoulos (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: