OCPBUGS-105321: pki: switch to ECDSA defaults and thread PKI profile to leaf certs - #10743
OCPBUGS-105321: pki: switch to ECDSA defaults and thread PKI profile to leaf certs#10743sanchezl wants to merge 7 commits into
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
📝 WalkthroughWalkthroughChangesConfigurable PKI now flows from effective profiles through Configurable PKI integration
Estimated code review effort: 4 (Complex) | ~60 minutes 🚥 Pre-merge checks | ✅ 14 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 golangci-lint (2.12.2)Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions Comment |
|
Skipping CI for Draft Pull Request. |
|
/test all |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
06ad91c to
9f4aa80
Compare
|
/test all |
|
/pipeline required |
|
Scheduling required tests: Scheduling tests matching the |
9f4aa80 to
65df21c
Compare
|
/test all |
|
/pipeline required |
|
Scheduling required tests: Scheduling tests matching the |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-10-techpreview |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f047f400-914e-11f1-8e35-4bb42ad1a5c4-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f1dfab00-914e-11f1-83c2-8d141c46cd05-0 |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-10-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f3b02540-914e-11f1-86a2-b0b4d2ce1f86-0 |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-fips |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f554fba0-914e-11f1-82cf-c1f8829a801b-0 |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-aws-ovn-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f745a810-914e-11f1-9a6b-7a95cb0904d2-0 |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-single-node-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f8b11ef0-914e-11f1-90de-25ab253cf8e2-0 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-usgov-ipi-custom-dns-mini-perm-tp-f7 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-c2s-ipi-disc-priv-fips-f28-tp-longduration-cloud |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-vsphere-short-cert-rotation-f7 |
|
/retest |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-aws-ovn-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-fips |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/249e1a00-920c-11f1-9cc4-163faa04d91a-0 |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-single-node-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/26b56140-920c-11f1-8d94-19d426bdf947-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/286d7180-920c-11f1-9f54-9a89a8838187-0 |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-10-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/cc8be8a0-920c-11f1-8706-b4850a407935-0 |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/cea66430-920c-11f1-87e4-30fd0c9941e5-0 |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-10-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d0574880-920c-11f1-9e16-9af2f5116d35-0 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-usgov-ipi-custom-dns-mini-perm-tp-f7 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d2985ee0-920c-11f1-99cb-afc3b7c6a653-0 |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-gcp-ovn-rhcos10-fips-techpreview-serial-1of2 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d4406990-920c-11f1-905d-c0eb4ac0c644-0 |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-gcp-ovn-rhcos10-fips-techpreview-serial-2of2 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d61c7c90-920c-11f1-89bc-7a08b5b5ed72-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d7f00410-920c-11f1-80eb-2644bbddb95d-0 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-vsphere-short-cert-rotation-f7 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-vsphere-ipi-proxy-fips-regen-cert-f14 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/7384cff0-920d-11f1-89ed-876ae8816ab9-0 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-c2s-ipi-disc-priv-fips-f28-tp-longduration-cloud |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/756f61e0-920d-11f1-9fcf-545afb7da02d-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/77357be0-920d-11f1-86ab-70841526a27b-0 |
|
/test e2e-aws-ovn |
Why
When ConfigurablePKI is enabled, the installer's
DefaultPKIProfile()returns a hardcoded RSA-4096 placeholder instead of library-go's defaults (ECDSA P-256 / P-384). Leaf certs also ignore the PKI profile entirely and always generate RSA-2048. This diverges from what day-2 operators (CKAO, CKMO) expect when they read the PKI CR for certificate rotation.What
DefaultPKIProfile()with library-go's versionSignerKeyParamsto carry a fullPKIProfile+ConfigurablePKIEnabledResolveCertificateConfigWhy this is safe
Zero blast radius for default installs. Every cert asset has a clear feature-gate guard:
When the feature gate is off (all production installs today), the existing hand-rolled crypto runs unchanged. The new library-go path only executes under TechPreview/CustomNoUpgrade with ConfigurablePKI explicitly enabled.
Agent flow preserved.
SignerKeyParamsremains zero-dependency —agent create certificatescontinues to work without install-config on disk, generating RSA-2048 certs via the legacy path. This pattern was established in PR #10595 after review by zaneb, tthvo, and andfasano (see PR #10595 discussion).Easy to cull. When ConfigurablePKI is promoted to always-on, the legacy branches and the old
GenerateSignedCertificate()/PrivateKey()functions can be deleted in one sweep. No behavioral dependencies between the two paths.Design decisions from prior PRs
This PR builds on the stacked PRs #10594 and #10595 (both merged). Key decisions inherited:
SignerKeyParams(PR CNTRLPLANE-2012: Wire signer certs to read PKI config via SignerKeyParams #10595, zaneb's review): avoids pulling InstallConfig validation into agent flowsAssetBase.LoadFromFile(PR CNTRLPLANE-2012: Wire signer certs to read PKI config via SignerKeyParams #10595, tthvo's feedback): strict YAML parsing without platform validationSignerKeyParamsinManifestsandagentManifestsTargetfor multi-step state persistenceagentCertificatesTarget(PR CNTRLPLANE-2012: Wire signer certs to read PKI config via SignerKeyParams #10595, zaneb): "install-config is not an input to this command"Commit walkthrough
The commits are ordered to build incrementally:
vendor: bump library-go— vendor-only, no functional changespki: replace local DefaultPKIProfile with library-go—pkg/types/pki/defaults.goonly, smallpki: extend SignerKeyParams—signerkey_params.go+ all signer asset dependency updatestls: add resolveKeyGen helpers— single new file, 24 linestls: add library-go code path to SelfSignedCertKey and SignedCertKey— core engine change incertkey.gotls: wire feature-gate branches— bulk mechanical change, same pattern in every cert assettls: fix cert types for library-go path— JournalCertKey → Peer (serves HTTPS and authenticates curl client with same cert), AdminKubeConfigClientCertKey → Client only (drops legacy ServerAuth — verified on live cluster including localhost-recovery), dead code removalCommit 6 is the largest but entirely mechanical — each asset follows the same pattern from commit 5. Review one asset (e.g.,
root.go) and spot-check the rest.Test plan
hack/build.sh)agent create certificatesintegration test passes without install-configSummary by CodeRabbit