Bug 2038934 - CSI driver operators should use the trusted CA bundle when cluster proxy is configured
Summary: CSI driver operators should use the trusted CA bundle when cluster proxy is c...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Storage
Version: 4.10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: 4.10.0
Assignee: Roman Bednář
QA Contact: Wei Duan
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-01-10 15:14 UTC by Fabio Bertinatto
Modified: 2022-03-10 16:38 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-03-10 16:38:09 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift alibaba-disk-csi-driver-operator pull 15 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 15:06:40 UTC
Github openshift aws-ebs-csi-driver-operator pull 146 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 17:46:16 UTC
Github openshift aws-efs-csi-driver-operator pull 33 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-25 14:51:15 UTC
Github openshift azure-disk-csi-driver-operator pull 40 0 None Merged Bug 2038934: Bump(library-go): to get leader election changes 2022-01-26 02:25:53 UTC
Github openshift azure-file-csi-driver-operator pull 22 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 17:46:19 UTC
Github openshift csi-driver-manila-operator pull 134 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 15:06:43 UTC
Github openshift gcp-pd-csi-driver-operator pull 43 0 None Merged Bug 2038934: Bump(library-go): to get leader election changes 2022-01-20 15:06:43 UTC
Github openshift ibm-vpc-block-csi-driver-operator pull 18 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 15:06:44 UTC
Github openshift openstack-cinder-csi-driver-operator pull 66 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 15:06:44 UTC
Github openshift vmware-vsphere-csi-driver-operator pull 69 0 None Merged Bug 2038934: Add custom CA bundle support 2022-01-20 15:06:44 UTC
Red Hat Product Errata RHSA-2022:0056 0 None None None 2022-03-10 16:38:22 UTC

Comment 1 Fabio Bertinatto 2022-01-10 15:17:56 UTC
Bumps for other operators:

CSO: https://github.com/openshift/cluster-storage-operator/pull/244
CSI Snapshot operator: https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/107

Comment 2 Fabio Bertinatto 2022-01-10 15:22:14 UTC
(Sorry for the multi-part description)

In addition to that, we need to make sure all those operators support a custom CA bundle. This PR contains an example on how to fix that using library-go's function hooks: https://github.com/openshift/gcp-pd-csi-driver-operator/pull/41/commits

Comment 3 Fabio Bertinatto 2022-01-10 15:28:21 UTC
Correction, this is the example PR: https://github.com/openshift/gcp-pd-csi-driver-operator/pull/40

Comment 12 Wei Duan 2022-01-28 09:33:40 UTC
Verified pass on azure-disk and azure-file

Comment 13 Wei Duan 2022-01-28 13:43:25 UTC
Currently Ali doen't support the http_proxy, so will check Ali CSI Driver when it is available.

Comment 18 Wei Duan 2022-02-23 10:35:29 UTC
Right now, IBM and Ali CSI Driver did not support proxy env, will verify them when available.
Will update the status to "Verified" as other CSIDriver passed, if hit the issue in IBM and Ali CSI Driver, I will file another bug to track.

Comment 20 errata-xmlrpc 2022-03-10 16:38:09 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: OpenShift Container Platform 4.10.3 security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2022:0056


Note You need to log in before you can comment on or make changes to this bug.