Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-12350

OAuth Proxy SAR cannot be overridden in Fuse Online 1.5

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • None
    • fuse-7.5-GA
    • Fuse Online
    • None
    • Fuse 7.6 - Sprint 56 (2/4)

      In previous releases of Fuse Online (1.4.x) we have been able to modify the OAuth Proxy DeploymentConfig that is set up by the Syndesis Operator, to remove any SAR checks.

      In Fuse Online 1.5 this appears to have changed, and continuous reconciliation of the OAuth Proxy means that we can no longer override the DeploymentConfig. The Syndesis Operator will revert the change.

      There is a DisableSarCheck flag on master, however this is not available in 1.5, so cannot be used as a workaround to implement the same functionality.

      This results in there being no way to allow any user logged into OpenShift to access the same console, as the SAR check is enforced. Which has resulted in a broken migration path when taking our (RHMI) clusters from 1.4 to 1.5.

            parichar@redhat.com Paul Richardson
            akeating-1 Aiden Keating (Inactive)
            Andrej Vano Andrej Vano
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: