Skip to content

pkg/daemon: support FIPS#826

Closed
runcom wants to merge 1 commit intoopenshift:masterfrom
runcom:fips-all-the-things
Closed

pkg/daemon: support FIPS#826
runcom wants to merge 1 commit intoopenshift:masterfrom
runcom:fips-all-the-things

Conversation

@runcom
Copy link
Copy Markdown
Member

@runcom runcom commented Jun 6, 2019

Signed-off-by: Antonio Murdaca runcom@linux.com

- What I did

Added a new FIPS field to MachineConfig to enable/disable FIPS on rhcos (disabled by default). This is, at this point, only intended as a day-2 operation.

The RHCOS I'm testing with hasn't yet rhe rhcos-tools to flip FIPS so I'm putting this on hold for now.

FIPS would also greatly benefit a dedicated CRD (oc edit fips?) - I'm experimenting with that but it will ofc require a new controller.

/hold

- How to verify it

added an e2e

- Description for the changelog

Signed-off-by: Antonio Murdaca <runcom@linux.com>
@openshift-ci-robot openshift-ci-robot added do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jun 6, 2019
@openshift-ci-robot
Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: runcom

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jun 6, 2019
@runcom
Copy link
Copy Markdown
Member Author

runcom commented Jun 6, 2019

/retest

@cgwalters
Copy link
Copy Markdown
Member

Wait dup of #800 right?

@runcom
Copy link
Copy Markdown
Member Author

runcom commented Jun 6, 2019

Wait dup of #800 right?

oh crap

@runcom runcom closed this Jun 6, 2019
@runcom runcom deleted the fips-all-the-things branch June 6, 2019 13:10
@openshift-ci-robot
Copy link
Copy Markdown
Contributor

@runcom: The following tests failed, say /retest to rerun them all:

Test name Commit Details Rerun command
ci/prow/e2e-aws-op 6adb9d5 link /test e2e-aws-op
ci/prow/e2e-etcd-quorum-loss 6adb9d5 link /test e2e-etcd-quorum-loss

Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@runcom runcom restored the fips-all-the-things branch June 25, 2019 10:09
@runcom runcom mentioned this pull request Jun 25, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants