-
Story
-
Resolution: Done
-
Critical
-
None
-
None
-
Strategic Product Work
-
5
-
False
-
None
-
False
-
OCPSTRAT-619 - Support Windows Containers in disconnected environments
-
-
-
WINC - Sprint 255
Description
This story covers supporting TLS in containerd's mirror registry config. Users may use registries that require TLS verification as mirrors –
- we should import all user provided certificates (through "user-ca-bundle" configmap or additionalTrustBundle field in install config) to the Windows nodes regardless of cluster settings
- We are currently missing certs provided through additionalTrustBundle field in install config, these are not injected into the ProxyCertsConfigMap that WMCO watches
- This is done today only when proxy is enabled
- the containerd hosts files should point mirrors to use the certificate bundle
Acceptance Criteria
- User custom certs for image registries are imported onto Windows nodes
- containerd uses these certs when pulling from mirror repos
- Disconnected CI job does not hit TLS error when pulling Windows images
- write docs calling out disconnected/image mirroring support - previous "docs"
- mark disconnected job as required
- links to
-
RHBA-2023:125706 Red Hat OpenShift for Windows Containers 10.16.0 product release
- mentioned on
(4 mentioned on)