-
Notifications
You must be signed in to change notification settings - Fork 1.8k
[WIP] OSDOCS#3995: ROSA - port 'Security' content from OCP #62384
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
85e8fba to
11f19ae
Compare
|
🤖 Fri Feb 09 18:30:23 - Prow CI generated the docs preview: https://62384--ocpdocs-pr.netlify.app |
11f19ae to
02911e0
Compare
|
@jaybeeunix @xueli181114 See this spreadsheet of errors I get from testing CLI commands in the security section. This list is still WIP. Thx. |
|
@xingxingxia @geliu2016 @sunilcio @wangke19 Could you please help to review for your components? thanks. |
_topic_maps/_topic_map_rosa.yml
Outdated
| - Name: Authenticating the cert-manager Operator for Red Hat OpenShift with GCP Workload Identity | ||
| File: cert-manager-authenticate-gcp | ||
| - Name: Authenticating the cert-manager Operator for Red Hat OpenShift on AWS | ||
| File: cert-manager-authentication-non-sts | ||
| - Name: Authenticating the cert-manager Operator for Red Hat OpenShift on GCP | ||
| File: cert-manager-authenticate-non-sts-gcp |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is ROSA document for ROSA cluster, then GCP documents cert-manager-authenticate-gcp and cert-manager-authenticate-non-sts-gcp are not applicable, need be removed.
cert-manager-operator-issuer-acme has GCP ambient credential section, that is also not applicable for ROSA cluster.
|
Apiserver topics look good to me. But I checked the link https://file.rdu.redhat.com/tlove/sd-port-security-tlove/upgrading/rosa-upgrading-cluster-prepare.html, we still has this upgrade path, I think that's a problem. |
|
For Compliance Operator, generally it is good. There are minor issues need to be updated:
|
02911e0 to
2cdebf9
Compare
d07bf0b to
aea07ed
Compare
507da05 to
61895ed
Compare
|
For Compliance Operator, below points are not applicable:
|
17b9bc2 to
551a033
Compare
@wangke19 When this was initially added, the admin acknowledgment was a new requirement. However, all major versions require this now. I will follow up with SRE to confirm. Thanks. |
|
Add one more important point for Compliance Operator: |
|
@sheriff-rh @bergerhoffer @xenolinux adding you for your awareness. |
7a7c941 to
d535ea0
Compare
|
/test validate-asciidoc |
1 similar comment
|
/test validate-asciidoc |
|
/retest |
|
/test validate-asciidoc |
0feb202 to
bf26e79
Compare
|
/retest |
97ded61 to
f07c973
Compare
|
/retest |
|
/retest-required |
f07c973 to
fdd4c69
Compare
| - Name: Deployments | ||
| Dir: deployments | ||
| Distros: openshift-rosa | ||
| Topics: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Put back this line. removing it breaks the build
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Whole stanza should look like:
Topics:
- Name: Deployments
Dir: deployments
Distros: openshift-rosa
Topics:
- Name: Custom domains for applications
File: osd-config-custom-domains-applications
a81d173 to
43efa43
Compare
43efa43 to
b579c62
Compare
|
@tmalove: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
@tmalove the netflix preview link doesn't seem to work any more. Is there another link somewhere? Eric Chapman and Austin Quam would like to review and share feedback if the review window is still open. https://62384--ocpdocs-pr.netlify.app/openshift-rosa/latest/welcome/index.html |
@codymant An updated preview is available, however VPN/network access is required. Let me know if Eric or Austin cannot access it. |
|
This PR is superseded by #72837. Refer to this PR for the Security porting project. |
|
@rhmdnd @BillDett @arendej @xingxingxia Use this latest PR for updates on the 'Security and compliance' porting. |
|
Refer to the latest PR to continue updates. |
@tmalove got it. For me, what I reviewed was for cert-manager as in my previous comment #62384 (comment) . In the new PR, seems cert-manager doc is totally removed. Anyway nvm, I'm transfering to @lunarwhite to continue review for cert-manager area in the new PR. |
This PR is to port the "Security and compliance" OCP content to ROSA. Reference that section only for comments, reviews, etc.
OSDOCS-3995
Version(s):
Link to docs preview (local build): https://file.rdu.redhat.com/tlove/sd-port-security-tlove/security/index.html (Updated 3/5)
QE review: