Skip to content

Commit 26ece1c

Browse files
author
Vadim Rutkovsky
committed
TLS registry: add description
This adds description to certificates managed by cluster-kube-apiserver-operator
1 parent 9bde41c commit 26ece1c

10 files changed

+44
-2
lines changed

bindata/assets/kube-apiserver/trusted-ca-cm.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,5 +5,6 @@ metadata:
55
name: trusted-ca-bundle
66
annotations:
77
"openshift.io/owning-component": "Networking / cluster-network-operator"
8+
"openshift.io/description": "CA used to recognize proxy servers. By default this will contain standard root CAs on the cluster-network-operator pod."
89
labels:
910
config.openshift.io/inject-trusted-cabundle: "true"

bindata/bootkube/manifests/configmap-admin-kubeconfig-client-ca.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
namespace: openshift-config
77
annotations:
88
"openshift.io/owning-component": "kube-apiserver"
9+
"openshift.io/description": "CA for kube-apiserver to recognize the system:master created by the installer."
910
data:
1011
ca-bundle.crt: |
1112
{{ .Assets | load "admin-kubeconfig-ca-bundle.crt" | indent 4 }}
12-

bindata/bootkube/manifests/configmap-csr-controller-ca.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
namespace: openshift-config-managed
77
annotations:
88
"openshift.io/owning-component": "kube-controller-manager"
9+
"openshift.io/description": "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager."
910
data:
1011
ca-bundle.crt: |
1112
{{ .Assets | load "kubelet-client-ca-bundle.crt" | indent 4 }}
12-

bindata/bootkube/manifests/secret-aggregator-client-signer.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ metadata:
88
"auth.openshift.io/certificate-not-after": {{ .Assets | load "aggregator-signer.crt" | notAfter }}
99
"auth.openshift.io/certificate-issuer": {{ .Assets | load "aggregator-signer.crt" | issuer }}
1010
"openshift.io/owning-component": "kube-apiserver"
11+
"openshift.io/description": "Signer for the kube-apiserver to create client certificates for aggregated apiservers to recognize as a front-proxy."
1112
type: kubernetes.io/tls
1213
data:
1314
tls.crt: {{ .Assets | load "aggregator-signer.crt" | base64 }}

bindata/bootkube/manifests/secret-control-plane-client-signer.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ metadata:
88
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-control-plane-signer.crt" | notAfter }}
99
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-control-plane-signer.crt" | issuer }}
1010
"openshift.io/owning-component": "kube-apiserver"
11+
"openshift.io/description": "Signer for kube-controller-manager and kube-scheduler client certificates."
1112
type: kubernetes.io/tls
1213
data:
1314
tls.crt: {{ .Assets | load "kube-control-plane-signer.crt" | base64 }}

bindata/bootkube/manifests/secret-kube-apiserver-to-kubelet-signer.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ metadata:
88
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | notAfter }}
99
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | issuer }}
1010
"openshift.io/owning-component": "kube-apiserver"
11+
"openshift.io/description": "Signer for the kube-apiserver-to-kubelet-client so kubelets can recognize the kube-apiserver."
1112
type: kubernetes.io/tls
1213
data:
1314
tls.crt: {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | base64 }}

bindata/bootkube/manifests/secret-loadbalancer-serving-signer.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ metadata:
88
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-lb-signer.crt" | notAfter }}
99
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-lb-signer.crt" | issuer }}
1010
"openshift.io/owning-component": "kube-apiserver"
11+
"openshift.io/description": "Signer used by the kube-apiserver operator to create serving certificates for the kube-apiserver via internal and external load balancers."
1112
type: kubernetes.io/tls
1213
data:
1314
tls.crt: {{ .Assets | load "kube-apiserver-lb-signer.crt" | base64 }}

bindata/bootkube/manifests/secret-localhost-serving-signer.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ metadata:
88
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-localhost-signer.crt" | notAfter }}
99
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-localhost-signer.crt" | issuer }}
1010
"openshift.io/owning-component": "kube-apiserver"
11+
"openshift.io/description": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via localhost."
1112
type: kubernetes.io/tls
1213
data:
1314
tls.crt: {{ .Assets | load "kube-apiserver-localhost-signer.crt" | base64 }}

bindata/bootkube/manifests/secret-service-network-serving-signer.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ metadata:
88
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-service-network-signer.crt" | notAfter }}
99
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-service-network-signer.crt" | issuer }}
1010
"openshift.io/owning-component": "kube-apiserver"
11+
"openshift.io/description": "Signer used by the kube-apiserver to create serving certificates for the kube-apiserver via the service network."
1112
type: kubernetes.io/tls
1213
data:
1314
tls.crt: {{ .Assets | load "kube-apiserver-service-network-signer.crt" | base64 }}

pkg/operator/certrotationcontroller/certrotationcontroller.go

Lines changed: 35 additions & 0 deletions
Large diffs are not rendered by default.

0 commit comments

Comments
 (0)