KEP-4322: Merge KEP-5339 into KEP-4322#6136
Conversation
mikeshng
commented
Jun 1, 2026
- One-line PR description: KEP-5339 (Plugin for Credentials in ClusterProfile) content has been moved into KEP-4322 (ClusterProfile API) since the base API and the credentials-related fields are expected to graduate together. KEP-5339 is marked as replaced.
- Issue link: Merge KEP-5339 (ClusterProfile Plugin Credentials) into KEP-4322 (ClusterProfile API) #6135
- Other comments: Combine KEP-5339 and KEP-4332 kubernetes-sigs/cluster-inventory-api#58
|
/assign @kahirokunn @lauralorenz @skitt |
| --> | ||
|
|
||
| Because of its interaction with authentication and credentials, particular | ||
| attention in the credential provider plugin design must be paid to security: |
There was a problem hiding this comment.
Could it be that Access Provider Plugins is the correct term instead of Credential Provider Plugins?
KEP-5339 (Plugin for Credentials in ClusterProfile) content has been moved into KEP-4322 (ClusterProfile API) since the base API and the credentials-related fields are expected to graduate together. KEP-5339 is marked as replaced. Signed-off-by: Mike Ng <ming@redhat.com>
2bbadbf to
cecc1c2
Compare
|
@mikeshng Should we remove "Push Model via Credentials in Secret (Not Recommended)"? Because there are already two plugins provided, the secret reader plugin and the kubeconfig secret reader plugin, which completely encapsulate the functionality of "Push Model via Credentials in Secret (Not Recommended)." I believe this feature is no longer necessary. The discussion in the following issue might be helpful: |
|
@kahirokunn yes, we should do that but under new PR. This PR should be focusing on merging the KEPs first. WDYT? |
|
Let’s do that. 👍 |
|
SGTM |
|
/approve Thanks! |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: kahirokunn, mikeshng, skitt The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |