Skip to content

Can recert be used instead of using patch openshift operators? #993

Open
@cfergeau

Description

We currently patch 2 openshift operators in order to get certificates with 1 year validity.
The recert tool has an option to extend the lifetime of a cluster certificate https://github.com/rh-ecosystem-edge/recert/blob/18d3284fa05747d6fb840b416bdcb7213dfa13a0/src/config/cli.rs#L185-L188 maybe it could be used instead of our patched operators.
I have some memories of openshift components rejecting certs valid for more than a month, but I don't know if this is still the case on newer openshift versions.

recert also has options to change the pull secret, the kubeadmin password, ... It can do this while kubelet is not running, and does its best to ensure costly container recreations will not be needed to use the new config, it could also be useful to look if this can be used to replace some crc code in a more efficient way (ie faster cluster startup)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions