Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

https://issues.redhat.com/browse/ACM-14417 Ver. Strategy doc #7222

Open
wants to merge 9 commits into
base: 2.12_stage
Choose a base branch
from

Conversation

oafischer
Copy link
Contributor

Train 19

Copy link

openshift-ci bot commented Nov 7, 2024

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: oafischer

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@zhujian7
Copy link
Contributor

zhujian7 commented Nov 12, 2024

@oafischer can we also mention the strategy when creating/importing a cluster, if it is a ROSA-HCP cluster, should check if the UseSystemTruststore is configured, for example:

1.6.4 Cluster creation
Add a pre-flight for the cluster creation
If your hub cluster API server certificate is issued by a public CA(e.g. Let’s Encrypt). For example, ROSA-HCP. Please refer to 1.6.18.1 to check if the hub server verification strategy is configured to UseSystemTruststore.

1.6.5 Cluster import
Add a pre-flight for the cluster import
If your hub cluster API server certificate is issued by a public CA(e.g. Let’s Encrypt). For example, ROSA-HCP. Please refer to 1.6.18.1 to check if the hub server verification strategy is configured to UseSystemTruststore.

@zhujian7
Copy link
Contributor

@elgnay please help take a review, thx!

@oafischer
Copy link
Contributor Author

@zhujian7 We can add the pre-flight info but I'm not sure where a good spot for it would be. In our creating and import doc, we do not have anything related to ROSA.

HCP content has also moved to OCP docs entirely in 2.12, so we don't have any HCP docs left in ACM docs where this could fit in either.

When reading pre-flight info, it sounds like it applies to more than just ROSA HCP. Is that the case?

@zhujian7
Copy link
Contributor

HCP content has also moved to OCP docs entirely in 2.12, so we don't have any HCP docs left in ACM docs where this could fit in either.

If so, I think it's OK without the pre-flight info. @elgnay WDYT?

@elgnay
Copy link
Contributor

elgnay commented Nov 13, 2024

@oafischer @zhujian7 I still think we need to add one more item to the prerequisites of cluster creation and cluster importing:

Since the default strategy 'UseAutoDetectedCABundle' may not work always, it necessary for the user to review the hub API server certificate verification strategy before they start creating or importing managed clusters.

@oafischer
Copy link
Contributor Author

@zhujian7 @elgnay Thanks for the feedback, I've added the requested info to the general prereq sections for import and create. I think it works well there. Let me know if it looks good now. Thanks!

@elgnay
Copy link
Contributor

elgnay commented Nov 14, 2024

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants