You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As expressed in the Kube PKI documentation, an external CA can be used instead of the kubeadm-generated one.
This would help to integrate FreeIPA and Kube better, the ultimate goal being to have cluster admins and developpers authenticated via FreeIPA-generated certificates containing their Kubernetes roles in the 'O' section
Describe the Need:
Enhance security
Current Alternative
Using certs generated by Kubernetes CA, but it is not related to freeipa at all
The text was updated successfully, but these errors were encountered:
End user reverse proxy: freeipa to generate kube admins/ops certificates, no additionnal CA to download but the frreipa one from an end user perspective
Technical Added value: apiserver to be protected by reverse proxy instead of firewalld rule.
Describe the Enhancement:
As expressed in the Kube PKI documentation, an external CA can be used instead of the kubeadm-generated one.
This would help to integrate FreeIPA and Kube better, the ultimate goal being to have cluster admins and developpers authenticated via FreeIPA-generated certificates containing their Kubernetes roles in the 'O' section
Describe the Need:
Enhance security
Current Alternative
Using certs generated by Kubernetes CA, but it is not related to freeipa at all
The text was updated successfully, but these errors were encountered: