Automating AWS IAM Credential Rotation in Red Hat OpenShift Container Platform
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Service on AWS (ROSA)
- 4
Issue
- How to auto-rotate AWS IAM credentials rather than manually for service accounts as they have to do it for their cluster frequently?
- How can the regular rotation of AWS service account access keys in OpenShift be automated, given the lack of a native method?
Resolution
Disclaimer: Links contained herein to external website(s) are provided for convenience only. Red Hat has not reviewed the links and is not responsible for the content or its availability. The inclusion of any link to an external website does not imply endorsement by Red Hat of the website or their entities, products or services. You agree that Red Hat is not responsible or liable for any loss or expenses that may result due to your use of (or reliance on) the external site or content.
-
For OSD and ROSA clusters, refer to Rotate AWS IAM User Access Keys in OSD/ROSA.
-
It's only supported manual credential rotation with Mint Mode in Cloud Credentials Operators:
Note: This credentials strategy is supported for only new OpenShift Container Platform clusters and must be configured during installation. It's not possible to reconfigure an existing cluster that uses a different credentials strategy to use this feature.
-
In the future with AWS Secure Token Service (STS), it will be a new function to allow creds to be automated, but it is not supported currently.
-
Master KCS collection to manual rotation AWS IAM credentials
Root Cause
OpenShift Cloud Credential Operator is in charge of generating credentials for a cloud provider and storing them as a secret in the namespace when they are needed.
This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.
Comments