Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-1232

Enable Azure managed identity with Azure AD workload identity for self-managed OpenShift for Azure Stack Hub

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • OCPSTRAT-10Install and update OpenShift on Infrastructure Providers
    • 100% To Do, 0% In Progress, 0% Done
    • 0
    • 0
    • Program Call

      Feature Overview

      • As a self-managed OpenShift on Azure administrator, I want to be create and manage OpenShift clusters using Azure managed identities for Azure resources for authentication, in conjunction with Azure AD workload identities to access Azure cloud resources securely in Azure Stack Hub.

      Goals

      • As an administrator, I want to deploy OpenShift 4 and run Operators on Azure using access controls (IAM roles) with temporary, limited privilege credentials in Microsoft Azure Government regions.
      • Note: The Azure MI/WI feature was introduced in OpenShift 4.14 for self-managed OpenShift (OCPSTRAT-513) and is available in all Azure regions where Azure MI/WI is available.
      • This does not yet work in Microsoft Azure Government regions and Azure Stack Hub, and this feature aims to address adding support for Azure Stack Hub..

      Requirements

      • Azure managed identities and workload identities must work for installation with all install methods including IPI and UPI, work with upgrades, and day-to-day cluster lifecycle operations.
      • Support HyperShift and non-HyperShift clusters.
      • Support use of Operators with Azure managed identities.
      • Support in all Azure regions where Azure managed identity and Azure AD workload identity is available. Note: Federated credentials is associated with Azure Managed Identity, and federated credentials is not available in all Azure regions.

       

      This Section: A list of specific needs or objectives that a Feature must deliver to satisfy the Feature.. Some requirements will be flagged as MVP. If an MVP gets shifted, the feature shifts. If a non MVP requirement slips, it does not shift the feature.

      Requirement Notes isMvp?
      CI - MUST be running successfully with test automation This is a requirement for ALL features. YES
      Release Technical Enablement Provide necessary release enablement details and documents. YES

      (Optional) Use Cases

      This Section:

      • Main success scenarios - high-level user stories
      • Alternate flow/scenarios - high-level user stories
      • ...

      Questions to answer…

      • ...

      Out of Scope

      Background, and strategic fit

      This Section: What does the person writing code, testing, documenting need to know? What context can be provided to frame this feature.

      Assumptions

      • ...

      Customer Considerations

      • ...

      Documentation Considerations

      Questions to be addressed:

      • What educational or reference material (docs) is required to support this product feature? For users/admins? Other functions (security officers, etc)?
      • Does this feature have doc impact?
      • New Content, Updates to existing content, Release Note, or No Doc Impact
      • If unsure and no Technical Writer is available, please contact Content Strategy.
      • What concepts do customers need to understand to be successful in [action]?
      • How do we expect customers will use the feature? For what purpose(s)?
      • What reference material might a customer want/need to complete [action]?
      • Is there source material that can be used as reference for the Technical Writer in writing the content? If yes, please link if available.
      • What is the doc impact (New Content, Updates to existing content, or Release Note)?

      References

            julim Ju Lim
            julim Ju Lim
            Antoni Segura Puimedon, Ju Lim, Marcos Entenza Garcia, Mike Worthington, Patrick Dillon
            Jianping Shu Jianping Shu
            Stephanie Stout Stephanie Stout
            Scott Dodson Scott Dodson
            Jeremiah Stuever Jeremiah Stuever
            Dave Mulford Dave Mulford
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: