Skip to content

[GH#87271] Add information about the openshift-service-ca.crt ConfigMap#87272

Open
Jamstah wants to merge 1 commit into
openshift:mainfrom
Jamstah:openshift-service-ca.crt
Open

[GH#87271] Add information about the openshift-service-ca.crt ConfigMap#87272
Jamstah wants to merge 1 commit into
openshift:mainfrom
Jamstah:openshift-service-ca.crt

Conversation

@Jamstah

@Jamstah Jamstah commented Jan 20, 2025

Copy link
Copy Markdown

The openshift kube-controller-manager maintains a ConfigMap in every namespace that publishes the service serving certifcate CA. Adding it to the documentation for users.

Version(s):
This functionality has existed since OpenShift 4.12.

Issue:
#87271

Link to docs preview:
https://87272--ocpdocs-pr.netlify.app/openshift-enterprise/latest/security/certificates/service-serving-certificate.html

QE review:

  • QE has approved this change.

Additional information:

@openshift-ci openshift-ci Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Jan 20, 2025
@openshift-ci

openshift-ci Bot commented Jan 20, 2025

Copy link
Copy Markdown

Hi @Jamstah. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@Jamstah

Jamstah commented Jan 20, 2025

Copy link
Copy Markdown
Author

Hi @openshift/team-documentation, can I please have an OK to test on this one.

@bergerhoffer

Copy link
Copy Markdown
Contributor

/ok-to-test

@openshift-ci openshift-ci Bot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Jan 20, 2025
@bergerhoffer

Copy link
Copy Markdown
Contributor

/retest

@bergerhoffer

Copy link
Copy Markdown
Contributor

@Jamstah thanks for submitting this! Something funky is going on with our tests, but I'll help move this along (need to get engineering/QE review as well).

I'll probably have some nits about the files - are you okay with making the updates if I point them out (and then squashing the commits afterward), or would you prefer me to take over the PR to make those final updates?

@bergerhoffer

Copy link
Copy Markdown
Contributor

/retest

@ocpdocs-previewbot

ocpdocs-previewbot commented Jan 20, 2025

Copy link
Copy Markdown

Comment thread modules/customize-certificates-access-default-service-serving-configmap.adoc Outdated
@bergerhoffer

Copy link
Copy Markdown
Contributor

@tkashem @wangke19 Can you confirm whether this is accurate and okay to document?

@Jamstah

Jamstah commented Jan 21, 2025

Copy link
Copy Markdown
Author

I'll probably have some nits about the files - are you okay with making the updates if I point them out (and then squashing the commits afterward), or would you prefer me to take over the PR to make those final updates?

However you like to work :)

@bergerhoffer

Copy link
Copy Markdown
Contributor

The branch/enterprise-4.19 label has been added to this PR.

This is because your PR targets the main branch and is labeled for enterprise-4.18. And any PR going into main must also target the latest version branch (enterprise-4.19).

If the update in your PR does NOT apply to version 4.19 onward, please re-target this PR to go directly into the appropriate version branch or branches (enterprise-4.x) instead of main.

@Jamstah

Jamstah commented Feb 25, 2025

Copy link
Copy Markdown
Author

@tkashem @wangke19 please review :)

@Jamstah

Jamstah commented Mar 18, 2025

Copy link
Copy Markdown
Author

@bergerhoffer is there anyone else who can approve?

@bergerhoffer

Copy link
Copy Markdown
Contributor

Sorry for the delay, I've pinged again, we'll try to get someone soon.

@bergerhoffer

Copy link
Copy Markdown
Contributor

The branch/enterprise-4.20 label has been added to this PR.

This is because your PR targets the main branch and is labeled for enterprise-4.19. And any PR going into main must also target the latest version branch (enterprise-4.20).

If the update in your PR does NOT apply to version 4.20 onward, please re-target this PR to go directly into the appropriate version branch or branches (enterprise-4.x) instead of main.

@Jamstah

Jamstah commented Aug 20, 2025

Copy link
Copy Markdown
Author

@tkashem @wangke19 @bergerhoffer Can I get a review on this? We'd really like to be able to rely on this behaviour but its hard to do that when its undocumented.

@openshift-ci openshift-ci Bot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Jan 19, 2026
@Jamstah

Jamstah commented Jan 19, 2026

Copy link
Copy Markdown
Author

/remove-lifecycle stale

@openshift-ci openshift-ci Bot removed the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Jan 19, 2026
@Jamstah Jamstah force-pushed the openshift-service-ca.crt branch from 3ec9a6e to 60e2e7e Compare January 19, 2026 12:13
Comment thread modules/customize-certificates-access-default-service-serving-configmap.adoc Outdated
@Jamstah

Jamstah commented Jan 19, 2026

Copy link
Copy Markdown
Author

@vrutkovs can you help me understand the ocpdocs-vale-bot issues? I don't see any differences between my new section and the section I copied from - is it new requirements?

@bergerhoffer

Copy link
Copy Markdown
Contributor

The branch/enterprise-4.22 label has been added to this PR.

This is because your PR targets the main branch and is labeled for enterprise-4.21. And any PR going into main must also target the latest version branch (enterprise-4.22).

If the update in your PR does NOT apply to version 4.22 onward, please re-target this PR to go directly into the appropriate version branch or branches (enterprise-4.x) instead of main.

@openshift-bot

Copy link
Copy Markdown

Issues go stale after 90d of inactivity.

Mark the issue as fresh by commenting /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.
Exclude this issue from closing by commenting /lifecycle frozen.

If this issue is safe to close now please do so with /close.

/lifecycle stale

@openshift-ci openshift-ci Bot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label May 5, 2026
@Jamstah

Jamstah commented May 5, 2026

Copy link
Copy Markdown
Author

/remove-lifecycle stale

@openshift-ci openshift-ci Bot removed the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label May 5, 2026
@jeana-redhat

Copy link
Copy Markdown
Contributor

The branch/enterprise-5.0 label has been added to this PR.

This is because your PR targets the main branch and is labeled for branch/enterprise-4.22. And any PR going into main must also target the latest version branch (branch/enterprise-5.0).

If the update in your PR does NOT apply to version 5.0 onward, please re-target this PR to go directly into the appropriate enterprise- version branch or branches instead of main.

@Jamstah

Jamstah commented Jun 9, 2026

Copy link
Copy Markdown
Author

@jeana-redhat @bergerhoffer this has been open for a very long time, how can we get it reviewed and progressed?

@jeana-redhat

Copy link
Copy Markdown
Contributor

@jeana-redhat @bergerhoffer this has been open for a very long time, how can we get it reviewed and progressed?

Hey @Jamstah - just glancing back through history, I don't have enough context to understand whether you got final technical SME approval. Is that aspect resolved?

If no, please get some SME to validate it.

If yes, please take the following actions to get it in the docs review queue:

  1. Add the string OSDOCS to the title (this is just so it hits our filter)
  2. Label for merge review with /label merge-review-needed

That should get you moving along again 🤓

@jeana-redhat

Copy link
Copy Markdown
Contributor

/retest

@jeana-redhat

Copy link
Copy Markdown
Contributor

(retest to refresh the PR builds)

@Jamstah

Jamstah commented Jun 9, 2026

Copy link
Copy Markdown
Author

@vrutkovs you have already looked at this, are you an SME who could approve it please?

@Jamstah Jamstah requested a review from vrutkovs June 9, 2026 12:41
@vrutkovs

vrutkovs commented Jun 9, 2026

Copy link
Copy Markdown

No longer working on OpenShift
/uncc

@openshift-ci openshift-ci Bot removed the request for review from vrutkovs June 9, 2026 12:56
@Jamstah

Jamstah commented Jun 9, 2026

Copy link
Copy Markdown
Author

@wangke19 can you suggest another reviewer for certificate docs please?

@bergerhoffer

Copy link
Copy Markdown
Contributor

@sanchezl @dgrisonnet @benluddy Who from the team might be good to help review this?

Comment thread modules/customize-certificates-access-default-service-serving-configmap.adoc Outdated
@Jamstah Jamstah force-pushed the openshift-service-ca.crt branch from 60e2e7e to 8ead76e Compare June 9, 2026 19:40
The openshift kube-controller-manager maintains a ConfigMap in every namespace that publishes the service serving certifcate CA.
Adding it to the documentation for users.

Signed-off-by: James Hewitt <james.hewitt@uk.ibm.com>
@Jamstah Jamstah force-pushed the openshift-service-ca.crt branch from 8ead76e to ac85cd5 Compare June 9, 2026 19:47
@openshift-ci

openshift-ci Bot commented Jun 9, 2026

Copy link
Copy Markdown

@Jamstah: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants