SSCSI-254: Configurable secret rotation and WIF support for SSCSI#2012
SSCSI-254: Configurable secret rotation and WIF support for SSCSI#2012chiragkyal wants to merge 1 commit into
Conversation
|
Skipping CI for Draft Pull Request. |
|
@chiragkyal: This pull request references SSCSI-254 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this: Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Signed-off-by: chiragkyal <ckyal@redhat.com>
00a6104 to
a49110c
Compare
|
/cc @mytreya-rh @dobsonj |
|
@chiragkyal: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
This enhancement proposal adds configurable secret rotation and workload identity federation (WIF) support to the OpenShift Secrets Store CSI Driver Operator via the
ClusterCSIDriverCR.Changes
CSIDriverConfigSpecwith a newSecretsStorediscriminated unionvariant containing
secretRotationandtokenRequestsfields.storage.k8s.io/v1CSIDriverobject (requiresRepublish,tokenRequests)--enable-secret-rotation,--rotation-poll-interval)rotation controller with kubelet-native
requiresRepublish.Tracking
/cc @mytreya-rh @dobsonj