[release-4.18] OCPBUGS-45524: Implement Managed Identities in HyperShift#5233
Conversation
|
@bryan-cox: This pull request references Jira Issue OCPBUGS-45524, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@bryan-cox: This pull request references Jira Issue OCPBUGS-45524, which is invalid:
Comment DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest |
1 similar comment
|
/retest |
704912a to
8285fba
Compare
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: bryan-cox The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest |
8285fba to
8b86bce
Compare
|
/jira refresh |
|
@bryan-cox: This pull request references Jira Issue OCPBUGS-45524, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/jira refresh |
|
@bryan-cox: This pull request references Jira Issue OCPBUGS-45524, which is valid. The bug has been moved to the POST state. 7 validation(s) were run on this bug
No GitHub users were found matching the public email listed for the QA contact in Jira (heli@redhat.com), skipping review request. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest-required |
|
/retest |
|
/lgtm |
This commit authenticates Azure KMS with certificate authentication in order to communicate with Azure Cloud API. The certificate is stored in an Azure key vault and mounted into the KAS pod through a Secrets Store CSI driver SecretProviderClass. Signed-off-by: Bryan Cox <brcox@redhat.com>
Reconcile the SecretProviderClass for the control plane operator for ARO HCP deployments. The SecretProviderClass is used by the Secrets Store CSI driver to mount a certificate to a volume in the control plane operator pod deployment. Signed-off-by: Bryan Cox <brcox@redhat.com>
Update the go.mod to include the specific commit that includes the changes to allow service principal with certificate to use a certificate . Signed-off-by: Bryan Cox <brcox@redhat.com>
This commit authenticates CAPZ with certificate authentication in order to communicate with Azure Cloud API. The certificate is stored in an Azure key vault and mounted into the capi-provider pod through a Secrets Store CSI driver SecretProviderClass. Signed-off-by: Bryan Cox <brcox@redhat.com>
This commit changes the authentication from client secret to client certificate as well as reconciling the SecretProviderClass for cloud provider for ARO HCP deployments. The SecretProviderClass is used by the Secrets Store CSI driver to mount a certificate to a volume in the azure-cloud-controller-manager pod's deployment. Signed-off-by: Bryan Cox <brcox@redhat.com>
Update the RBAC for the HyperShift Operator (HO) to include 'update' for secrets-store.csi.x-k8s.io on managed Azure deployments of the HO. Signed-off-by: Bryan Cox <brcox@redhat.com>
8b86bce to
4f0a989
Compare
|
/hold |
|
/test e2e-aks |
|
/retest |
|
@bryan-cox: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/retest-required |
|
/hold cancel |
|
/lgtm |
|
@bryan-cox: Jira Issue OCPBUGS-45524: All pull requests linked via external trackers have merged: Jira Issue OCPBUGS-45524 has been moved to the MODIFIED state. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[ART PR BUILD NOTIFIER] Distgit: hypershift |
What this PR does / why we need it:
Manual backport of
Which issue(s) this PR fixes (optional, use
fixes #<issue_number>(, fixes #<issue_number>, ...)format, where issue_number might be a GitHub issue, or a Jira story:Fixes OCPBUGS-45524
Checklist