BUG 1670700: data/data/bootstrap: set metric-ca flags for kube-etcd-signer-server#1483
Conversation
Signed-off-by: Sam Batschelet <sbatsche@redhat.com>
/test unit |
|
/retest |
s-urbaniak
left a comment
There was a problem hiding this comment.
/approve
As discussed out of band: this, and especially the other corresponding PR https://github.com/openshift/installer/pull/1291/files "just" changes the secret location (and adds a configmap for the CA) of the etcd client secrets/cert. The fact that they are proxied is an opaque fact for the cluster monitoring operator. Note that the CA has to be loaded from a configmap now and the secret location has to be changed in the code that was introduced in openshift/cluster-monitoring-operator#239
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: abhinavdahiya, hexfusion, s-urbaniak The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This PR adds metric-signer CA's to kube-etcd-signer-server as part of voyage to etcd metrics by default. The eventual result is the etcd static pod procuring TLS certs with a separate chain of trust vs
PeerandServer.