Skip to content

CNTRLPLANE-4025: feat(azure): support managed HSM for KMS encryption - #9199

Merged
openshift-merge-bot[bot] merged 6 commits into
openshift:mainfrom
hlipsig:hlipsig-azure-hsm-support
Aug 21, 2026
Merged

openshift-merge-bot[bot] merged 6 commits into
openshift:mainfrom
hlipsig:hlipsig-azure-hsm-support

Conversation

@hlipsig

@hlipsig hlipsig commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does / why we need it

Adds Azure Managed HSM support for control-plane KMS encryption. The API distinguishes Azure Key Vault from Managed HSM, and the selected type is carried through endpoint resolution, sidecar configuration, validation, status, rotation, and provider identity generation.

Existing Azure Key Vault provider names and fingerprints remain unchanged when keyVaultType is omitted or explicitly set to KeyVault.

Compatibility and limitations

  • Managed HSM requires an OpenShift 4.22 or later HostedCluster release, including 4.22 prerelease payloads.
  • Azure Public, US Government, China, German, and Bleu cloud Key Vault and Managed HSM endpoints are supported.
  • Managed HSM is unsupported on earlier releases because their control plane operator does not configure its endpoint or authentication scope.
  • .spec.secretEncryption.kms.azure.keyVaultType applies to the entire Azure KMS configuration, including active, backup, status-derived, and rotation target keys.
  • keyVaultType is immutable. Existing HostedClusters cannot migrate between Key Vault and Managed HSM; a new HostedCluster is required.
  • Downgrading a HostedCluster after enabling Managed HSM is unsupported.
  • Custom Azure Stack Key Vault endpoints are not supported.

Which issue(s) this PR fixes

Fixes https://redhat.atlassian.net/browse/OCPSTRAT-3549

Special notes for reviewers

The Azure Managed HSM path was manually verified against a live subscription before review. End-to-end revalidation of the review fixes is in progress.

Checklist

  • Subject and description added to both commit and PR.
  • Relevant issue referenced.
  • Documentation included.
  • Unit and envtest coverage included.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 31, 2026
@openshift-ci

openshift-ci Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci openshift-ci Bot added do-not-merge/needs-area needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/platform/azure PR/issue for Azure (AzurePlatform) platform and removed do-not-merge/needs-area labels Jul 31, 2026
@coderabbitai

coderabbitai Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Azure KMS now supports Azure Managed HSM in addition to Azure Key Vault. The API adds an optional vault-type field with Key Vault as the default. Validation enforces matching vault types for active and backup keys and prevents changing the active key’s type. Azure utilities parse and generate service-specific endpoints. Cluster configuration, KAS runtime arguments, provider names, and fingerprints preserve the vault type. Compatibility tests cover legacy JSON and identity behavior.

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant ClusterCLI
  participant HostedCluster
  participant AzureUtilities
  participant KASKMS
  User->>ClusterCLI: Provide Azure encryption key identifier
  ClusterCLI->>HostedCluster: Set key and KeyVaultType
  HostedCluster->>AzureUtilities: Parse key and resolve DNS suffix
  AzureUtilities-->>HostedCluster: Return Azure encryption key metadata
  HostedCluster->>KASKMS: Propagate active and target key metadata
  KASKMS->>KASKMS: Add --managed-hsm when required
Loading
🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The changed tests add only static Go t.Run names; no Ginkgo It, Describe, Context, or similar declarations use dynamic values.
Test Structure And Quality ✅ Passed The PR adds no Ginkgo code: changed Go tests use testing.T and local functions, with no Describe/It, BeforeEach/AfterEach, Eventually, or cluster resource operations.
Topology-Aware Scheduling Compatibility ✅ Passed The aggregate diff adds no affinity, topology spread, node selector, toleration, PDB, replica, or rollout constraints; controller changes only carry Azure KMS vault type and add a container argument.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The PR adds standard Go unit tests and declarative CRD validation cases, not new Ginkgo e2e tests; no added Ginkgo networking or external connection code was found.
No-Weak-Crypto ✅ Passed The PR adds no MD5, SHA-1, DES, RC4, Blowfish, or ECB use, custom crypto, or secret comparisons; fingerprints continue to use SHA-256.
Container-Privileges ✅ Passed The full PR diff adds no privileged, hostPID, hostNetwork, hostIPC, SYS_ADMIN, root, or allowPrivilegeEscalation settings; KMS changes only add --managed-hsm and key identity handling.
No-Sensitive-Data-In-Logs ✅ Passed The feature diff adds no production logging calls. Runtime logs retain only non-sensitive fingerprints and status messages; Azure key fields are used in arguments or hashed provider names, not logs.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding Azure Managed HSM support for KMS encryption.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms.go (1)

143-153: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Add rotation-path coverage for KeyVaultType.

Add a deriveKMSKeys test with Managed HSM active and target status keys. Cover both promotion branches. Assert that both returned keys retain ManagedHSM; otherwise a future status-copy regression can remove the Managed HSM provider identity and runtime flag.

As per coding guidelines, “Unit test any code changes and additions.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms.go` around
lines 143 - 153, Add rotation-path coverage for KeyVaultType in deriveKMSKeys:
create a test with active and target Azure status keys using ManagedHSM,
exercise both key-promotion branches, and assert both returned keys preserve
ManagedHSM. Ensure the test guards against status-copy regressions that drop the
provider identity or runtime flag.

Source: Coding guidelines

🧹 Nitpick comments (2)
control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go (1)

532-548: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use fixed legacy identity fixtures.

Both tests calculate the baseline with the changed implementation. They prove normalization only. They do not prove compatibility with prior releases. Add fixed N-1 Key Vault provider-name and fingerprint fixtures. Assert that omitted and explicit KeyVault values match those fixtures.

  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go#L532-L548: Assert the provider name against a fixed legacy value.
  • support/secretencryption/fingerprint_test.go#L29-L43: Assert the fingerprint against a fixed legacy value.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go`
around lines 532 - 548, The tests currently derive the legacy baseline from the
changed implementation instead of verifying N-1 compatibility. In
control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go
lines 532-548, update TestAzureKMSProviderName to compare both omitted and
explicit KeyVault configurations against a fixed legacy provider-name fixture,
while retaining the ManagedHSM distinction. In
support/secretencryption/fingerprint_test.go lines 29-43, update the fingerprint
test to compare omitted and explicit KeyVault configurations against a fixed
legacy fingerprint fixture; do not calculate either baseline from the
implementation under test.
support/azureutil/azureutil.go (1)

448-451: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Wrap the DNS suffix resolution error.

Add operation context before returning err. This identifies GetKeyVaultFQDN as the failed operation.

As per coding guidelines, wrap errors with context when rethrowing.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@support/azureutil/azureutil.go` around lines 448 - 451, In GetKeyVaultFQDN,
wrap the error returned by GetKeyVaultDNSSuffix with operation context
identifying GetKeyVaultFQDN before returning it, while preserving the existing
empty-string result and error flow.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@api/hypershift/v1beta1/azure.go`:
- Around line 917-921: Add envtest coverage for the AzureKMSSpec CEL
validations, exercising omitted vault types, Key Vault versus Managed HSM
mismatches, immutable activeKey.keyVaultType updates, and updates from an
omitted type to explicit KeyVault. Use the envtest API server to create and
update resources so CRD defaults and XValidation rules execute, and assert each
expected validation outcome.

In `@api/hypershift/v1beta1/etcdbackup_types.go`:
- Around line 181-187: Update the encryptionKeyURL validation patterns in
api/hypershift/v1beta1/etcdbackup_types.go at lines 181-187, 251-256, and
350-355 to accept Managed HSM hostnames ending in managedhsm.azure.net,
managedhsm.azure.cn, or managedhsm.usgovcloudapi.net, while preserving the
existing URL structure and validation constraints at all three sites.

In `@support/azureutil/azureutil_test.go`:
- Around line 694-739: Extend the TestGetKeyVaultDNSSuffix table with a China
cloud ManagedHSM case using the appropriate Azure China cloud identifier and
assert the expected managedhsm.azure.cn suffix. Keep the existing error and
other cloud cases unchanged.

In `@support/azureutil/azureutil.go`:
- Around line 487-496: Update the hostname classification before assigning
KeyVaultType in the AzureEncryptionKey construction: normalize host case and
validate it against exact approved Managed HSM and Key Vault hostname suffixes
using an allow-list. Set ManagedHSM only for an approved Managed HSM suffix,
KeyVault only for an approved Key Vault suffix, and reject or otherwise preserve
the existing invalid-host handling for unapproved domains; do not use an
unanchored substring check.

---

Outside diff comments:
In `@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms.go`:
- Around line 143-153: Add rotation-path coverage for KeyVaultType in
deriveKMSKeys: create a test with active and target Azure status keys using
ManagedHSM, exercise both key-promotion branches, and assert both returned keys
preserve ManagedHSM. Ensure the test guards against status-copy regressions that
drop the provider identity or runtime flag.

---

Nitpick comments:
In
`@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go`:
- Around line 532-548: The tests currently derive the legacy baseline from the
changed implementation instead of verifying N-1 compatibility. In
control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go
lines 532-548, update TestAzureKMSProviderName to compare both omitted and
explicit KeyVault configurations against a fixed legacy provider-name fixture,
while retaining the ManagedHSM distinction. In
support/secretencryption/fingerprint_test.go lines 29-43, update the fingerprint
test to compare omitted and explicit KeyVault configurations against a fixed
legacy fingerprint fixture; do not calculate either baseline from the
implementation under test.

In `@support/azureutil/azureutil.go`:
- Around line 448-451: In GetKeyVaultFQDN, wrap the error returned by
GetKeyVaultDNSSuffix with operation context identifying GetKeyVaultFQDN before
returning it, while preserving the existing empty-string result and error flow.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: e764f6e8-a327-4317-90a4-678e4eeb96c7

📥 Commits

Reviewing files that changed from the base of the PR and between 53daedc and 5cd7646.

⛔ Files ignored due to path filters (41)
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hcpetcdbackups.hypershift.openshift.io/HCPEtcdBackup.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/AAA_ungated.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/ClusterUpdateAcceptRisks.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/ClusterVersionOperatorConfiguration.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/ExternalOIDC.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/ExternalOIDCWithUIDAndExtraClaimMappings.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/ExternalOIDCWithUpstreamParity.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/GCPPlatform.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/HCPEtcdBackup.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/HyperShiftOnlyDynamicResourceAllocation.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/ImageStreamImportMode.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/KMSEncryptionProvider.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/OpenStack.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedclusters.hypershift.openshift.io/TLSAdherence.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/AAA_ungated.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/ClusterUpdateAcceptRisks.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/ClusterVersionOperatorConfiguration.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/ExternalOIDC.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/ExternalOIDCWithUIDAndExtraClaimMappings.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/ExternalOIDCWithUpstreamParity.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/GCPPlatform.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/HCPEtcdBackup.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/HyperShiftOnlyDynamicResourceAllocation.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/ImageStreamImportMode.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/KMSEncryptionProvider.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/OpenStack.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests/hostedcontrolplanes.hypershift.openshift.io/TLSAdherence.yaml is excluded by !**/zz_generated.featuregated-crd-manifests/**
  • client/applyconfiguration/hypershift/v1beta1/azurekmskey.go is excluded by !client/**
  • cmd/install/assets/crds/hypershift-operator/tests/hcpetcdbackups.hypershift.openshift.io/techpreview.hcpetcdbackups.status.testsuite.yaml is excluded by !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/tests/hcpetcdbackups.hypershift.openshift.io/techpreview.hcpetcdbackups.validation.testsuite.yaml is excluded by !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/tests/hostedclusters.hypershift.openshift.io/stable.hostedclusters.kms.testsuite.yaml is excluded by !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hcpetcdbackups-CustomNoUpgrade.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hcpetcdbackups-TechPreviewNoUpgrade.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hostedclusters-Hypershift-CustomNoUpgrade.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hostedclusters-Hypershift-Default.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hostedclusters-Hypershift-TechPreviewNoUpgrade.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hostedcontrolplanes-Hypershift-CustomNoUpgrade.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hostedcontrolplanes-Hypershift-Default.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/hypershift-operator/zz_generated.crd-manifests/hostedcontrolplanes-Hypershift-TechPreviewNoUpgrade.crd.yaml is excluded by !**/zz_generated.crd-manifests/**, !cmd/install/assets/**/*.yaml
  • vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/azure.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/etcdbackup_types.go is excluded by !vendor/**, !**/vendor/**
📒 Files selected for processing (14)
  • api/hypershift/v1beta1/azure.go
  • api/hypershift/v1beta1/azure_test.go
  • api/hypershift/v1beta1/etcdbackup_types.go
  • cmd/cluster/azure/create.go
  • cmd/util/azure_flag_descriptions.go
  • control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/reencryption/reencryption.go
  • support/azureutil/azureutil.go
  • support/azureutil/azureutil_test.go
  • support/secretencryption/fingerprint.go
  • support/secretencryption/fingerprint_test.go

Comment thread api/hypershift/v1beta1/azure.go Outdated
Comment thread api/hypershift/v1beta1/etcdbackup_types.go Outdated
Comment thread support/azureutil/azureutil_test.go
Comment thread support/azureutil/azureutil.go Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.go (1)

119-171: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Keep legacy Key Vault rotation coverage.

The table now covers Azure rotation only with KeyVaultType: ManagedHSM. It does not exercise the API default where KeyVaultType is omitted. Add equivalent read-only and promotion cases for the default Key Vault path. This protects legacy provider identity and rotation behavior.

Based on the PR objective to preserve legacy Key Vault provider identities, keep a default-path regression case in this table.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.go`
around lines 119 - 171, Add equivalent read-only and promotion table cases
alongside the existing Managed HSM cases, leaving Azure KeyVaultType omitted to
exercise the legacy default Key Vault path. Use the same v1/v2 rotation states
and validations in the kmsWriteReadKeys callbacks, including provider identity
and key versions, so both rotation phases preserve legacy behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.go`:
- Around line 193-197: Update mustAWSProviderName and mustAzureProviderName to
capture and assert errors returned by their respective KMS provider-name
helpers, failing the test explicitly when hashing fails; only return the
provider name after successful validation.

---

Nitpick comments:
In `@control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.go`:
- Around line 119-171: Add equivalent read-only and promotion table cases
alongside the existing Managed HSM cases, leaving Azure KeyVaultType omitted to
exercise the legacy default Key Vault path. Use the same v1/v2 rotation states
and validations in the kmsWriteReadKeys callbacks, including provider identity
and key versions, so both rotation phases preserve legacy behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 38821765-09e3-4ac2-893f-74944077ce9a

📥 Commits

Reviewing files that changed from the base of the PR and between 69efce8 and 312024b.

⛔ Files ignored due to path filters (1)
  • cmd/install/assets/crds/hypershift-operator/tests/hostedclusters.hypershift.openshift.io/stable.hostedclusters.kms.testsuite.yaml is excluded by !cmd/install/assets/**/*.yaml
📒 Files selected for processing (4)
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.go
  • support/azureutil/azureutil.go
  • support/secretencryption/fingerprint_test.go
🚧 Files skipped from review as they are similar to previous changes (3)
  • support/secretencryption/fingerprint_test.go
  • support/azureutil/azureutil.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms/azure_test.go

Comment thread control-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.go Outdated
@openshift-ci openshift-ci Bot added the area/documentation Indicates the PR includes changes for documentation label Jul 31, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🧹 Nitpick comments (1)
docs/content/how-to/azure/create-azure-cluster-with-options.md (1)

27-27: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Normalize the code blocks for Markdown validation.

Add appropriate language identifiers such as bash, yaml, and text. Apply the repository-configured code-block style consistently to resolve MD040 and MD046.

Also applies to: 56-56, 67-67, 108-108, 138-138, 176-176, 181-181, 187-187, 200-200, 208-208, 217-217, 222-222, 244-244, 260-260, 269-269

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/content/how-to/azure/create-azure-cluster-with-options.md` at line 27,
Normalize every fenced code block in create-azure-cluster-with-options.md by
adding the appropriate language identifier, such as bash, yaml, or text, and
apply the repository’s configured fence style consistently so all affected
blocks satisfy MD040 and MD046.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/content/how-to/azure/create-azure-cluster-with-options.md`:
- Line 4: Update the link in the introductory sentence to use descriptive text
identifying the destination, such as “Azure cluster setup without additional
options,” while preserving the existing create-azure-cluster-on-aks.md target.
- Line 241: Remove the leading space inside the inline code span for
azure-kms-provider-active in the kube-apiserver verification sentence,
preserving the surrounding wording and formatting.
- Line 18: Correct the spelling in the documentation: update the line-18 wording
to “access the key vault” and capitalize “Ephemeral” on line 98. Run make
verify-codespell to verify the Markdown changes.
- Line 207: Update the HyperShift CLI command instructions around the step 1d
reference to point to step 1c, and remove backticks surrounding the shell
arguments in the fenced command block so they are passed literally rather than
interpreted as command substitution.
- Around line 157-164: Expand the Azure KMS procedure beyond the compatibility
note to document Managed HSM setup, including resource creation, key-identifier
configuration, supported endpoint forms, required role assignment, and Managed
HSM-specific provider or fingerprint verification output. Use the existing KMS
setup and verification sections as the integration points; if Managed HSM
details cannot be added, explicitly label those steps and outputs as Azure Key
Vault-only.

---

Nitpick comments:
In `@docs/content/how-to/azure/create-azure-cluster-with-options.md`:
- Line 27: Normalize every fenced code block in
create-azure-cluster-with-options.md by adding the appropriate language
identifier, such as bash, yaml, or text, and apply the repository’s configured
fence style consistently so all affected blocks satisfy MD040 and MD046.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: eceaa7a8-cda2-43fd-b977-f99c49ffdfb7

📥 Commits

Reviewing files that changed from the base of the PR and between 01b108d and ee56309.

📒 Files selected for processing (1)
  • docs/content/how-to/azure/create-azure-cluster-with-options.md

Comment thread docs/content/how-to/azure/create-azure-cluster-with-options.md Outdated
Comment thread docs/content/how-to/azure/create-azure-cluster-with-options.md Outdated
Comment thread docs/content/how-to/azure/create-azure-cluster-with-options.md Outdated
Comment thread docs/content/how-to/azure/create-azure-cluster-with-options.md Outdated
Comment thread docs/content/how-to/azure/create-azure-cluster-with-options.md Outdated
Comment thread api/hypershift/v1beta1/etcdbackup_types.go Outdated
@hlipsig
hlipsig force-pushed the hlipsig-azure-hsm-support branch 3 times, most recently from 4a9719a to f58d3be Compare August 4, 2026 21:31
@openshift-ci openshift-ci Bot added the area/testing Indicates the PR includes changes for e2e testing label Aug 4, 2026
@hlipsig
hlipsig force-pushed the hlipsig-azure-hsm-support branch from f58d3be to 1de9b4f Compare August 5, 2026 01:48
@openshift-ci openshift-ci Bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Aug 5, 2026
@github-actions
github-actions Bot temporarily deployed to docs-preview/pr-9199 August 5, 2026 01:55 Inactive
@codecov

codecov Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 81.43713% with 31 lines in your changes missing coverage. Please review.
✅ Project coverage is 45.92%. Comparing base (afd9035) to head (d3ea9f6).
⚠️ Report is 18 commits behind head on main.

Files with missing lines Patch % Lines
support/azureutil/azureutil.go 83.75% 12 Missing and 1 partial ⚠️
...trollers/hostedcluster/hostedcluster_controller.go 68.75% 9 Missing and 1 partial ⚠️
cmd/infra/azure/create.go 0.00% 2 Missing ⚠️
cmd/infra/azure/destroy.go 0.00% 2 Missing ⚠️
...goperator/controllers/reencryption/reencryption.go 88.23% 2 Missing ⚠️
cmd/cluster/azure/create.go 0.00% 1 Missing ⚠️
...ostedcontrolplane/hostedcontrolplane_controller.go 0.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #9199      +/-   ##
==========================================
+ Coverage   45.85%   45.92%   +0.06%     
==========================================
  Files         781      781              
  Lines       97936    98061     +125     
==========================================
+ Hits        44911    45032     +121     
- Misses      49959    49964       +5     
+ Partials     3066     3065       -1     
Files with missing lines Coverage Δ
...rator/controllers/hostedcontrolplane/v2/kas/kms.go 48.12% <100.00%> (+3.00%) ⬆️
...controllers/hostedcontrolplane/v2/kas/kms/azure.go 96.67% <100.00%> (+0.22%) ⬆️
support/secretencryption/fingerprint.go 95.65% <100.00%> (+0.41%) ⬆️
support/secretencryption/keystatus.go 75.75% <100.00%> (ø)
cmd/cluster/azure/create.go 46.05% <0.00%> (-0.09%) ⬇️
...ostedcontrolplane/hostedcontrolplane_controller.go 47.24% <0.00%> (ø)
cmd/infra/azure/create.go 8.65% <0.00%> (ø)
cmd/infra/azure/destroy.go 21.95% <0.00%> (ø)
...goperator/controllers/reencryption/reencryption.go 72.16% <88.23%> (+2.82%) ⬆️
...trollers/hostedcluster/hostedcluster_controller.go 54.92% <68.75%> (+0.10%) ⬆️
... and 1 more
Flag Coverage Δ
cmd-support 39.14% <81.05%> (+0.10%) ⬆️
cpo-hostedcontrolplane 48.24% <95.65%> (+0.07%) ⬆️
cpo-other 46.12% <88.23%> (+0.10%) ⬆️
hypershift-operator 57.06% <68.75%> (+0.01%) ⬆️
other 34.38% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions
github-actions Bot temporarily deployed to docs-preview/pr-9199 August 5, 2026 02:10 Inactive
@github-actions
github-actions Bot temporarily deployed to docs-preview/pr-9199 August 5, 2026 02:53 Inactive
@hlipsig

hlipsig commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor Author

This is ready to review, but I don't have a prow job yet since we need to add some stuff to the Azure subscription. Manual verification passed and I have the environment available for use if anyone wants to take a look at it.

@hlipsig
hlipsig marked this pull request as ready for review August 5, 2026 02:57
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Aug 5, 2026
@hlipsig

hlipsig commented Aug 19, 2026

Copy link
Copy Markdown
Contributor Author

Fresh-cluster Azure end-to-end validation completed against commit 216b82e9f.

Test setup:

  • HO: hlipsighsmacr.azurecr.io/hypershift:pr9199-216b82e9f
  • CPO: hlipsighsmacr.azurecr.io/control-plane-operator:pr9199-216b82e9f
  • HostedCluster release: 4.22.8
  • Azure KMS provider: the component from accepted 5.0 nightly 5.0.0-0.nightly-2026-08-18-203845. The 4.22 payload component contains the previously known malformed Managed HSM suffix bug; its endpoint became <name>.https//managedhsm.azure.net. The 5.0 component correctly used https://<name>.managedhsm.azure.net/.

Results:

  • Managed HSM success: created a new HostedCluster from scratch with keyVaultType: ManagedHSM. ValidAzureKMSConfig=True; the active KMS sidecar had --managed-hsm, both the KMS sidecar and kube-apiserver were ready, and a guest Secret's raw etcd value began with k8s:enc:kms:v2:.
  • Default Key Vault success: created a second new HostedCluster and explicitly removed keyVaultType, leaving the field absent. ValidAzureKMSConfig=True; the KMS sidecar used the standard vault.azure.net endpoint without Managed HSM mode, and a guest Secret's raw etcd value also began with k8s:enc:kms:v2:.
  • Invalid mismatch failure: created a third initial manifest with keyVaultType: ManagedHSM but a standard Key Vault key/name. As expected, ValidAzureKMSConfig=False; validation attempted <key-vault-name>.managedhsm.azure.net and failed DNS lookup. It never reported success-shaped status.

@hlipsig

hlipsig commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

/validated by @hlipsig see full evidence above

@cblecker

Copy link
Copy Markdown
Member

/pipeline required

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aks-5-0
/test e2e-aws-5-0
/test e2e-aks
/test e2e-aws
/test e2e-aws-upgrade-hypershift-operator
/test e2e-kubevirt-aws-ovn-reduced
/test e2e-v2-aws
/test e2e-v2-azure-self-managed
/test e2e-v2-gke

@cblecker

Copy link
Copy Markdown
Member

/cc

@hlipsig

hlipsig commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

/retest

1 similar comment
@hlipsig

hlipsig commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

/retest

Comment thread api/hypershift/v1beta1/azure.go
@JoelSpeed

Copy link
Copy Markdown
Contributor

/approve

hlipsig and others added 6 commits August 20, 2026 08:21
- Add AzureKMSKeyVaultType to AzureKMSSpec with backward-compatible immutability validation
- Support Public, US Government, China, German, and Bleu Azure clouds
- Accept Managed HSM encryption key URLs and regenerate feature-gated API manifests

Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com>
Commit-Message-Assisted-by: Claude (via Claude Code)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Regenerate install CRDs and validation suites for Managed HSM and sovereign clouds
- Cover immutable vault type transitions and all supported Azure key URL suffixes
- Update the AzureKMSSpec client and vendored HyperShift API types

Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com>
Commit-Message-Assisted-by: Claude (via Claude Code)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Propagate the detected vault type into AzureKMSSpec during cluster creation
- Expose all supported Azure cloud environments in CLI help
- Document Key Vault and Managed HSM encryption key URL formats

Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com>
Commit-Message-Assisted-by: Claude (via Claude Code)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Resolve Key Vault and Managed HSM endpoints across all supported Azure clouds
- Preserve legacy Key Vault fingerprints while distinguishing Managed HSM keys
- Gate Managed HSM on OpenShift 4.22 without masking release resolution failures

Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com>
Commit-Message-Assisted-by: Claude (via Claude Code)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Pass Managed HSM mode to both active and backup Azure KMS provider sidecars
- Use one immutable vault type for active, backup, and rotation target keys
- Preserve legacy Key Vault provider names while distinguishing Managed HSM providers

Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com>
Commit-Message-Assisted-by: Claude (via Claude Code)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Describe supported Azure KMS services, clouds, and minimum OpenShift version
- Regenerate the API reference and aggregated documentation

Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com>
Commit-Message-Assisted-by: Claude (via Claude Code)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hlipsig

hlipsig commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

/validated by @hlipsig recent changes were rebase only.

@bryan-cox bryan-cox left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aks-5-0
/test e2e-aws-5-0
/test e2e-aks
/test e2e-aws
/test e2e-aws-upgrade-hypershift-operator
/test e2e-kubevirt-aws-ovn-reduced
/test e2e-v2-aws
/test e2e-v2-azure-self-managed
/test e2e-v2-gke

@openshift-ci

openshift-ci Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bryan-cox, hlipsig, JoelSpeed, muraee, yuqi-zhang

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

@hlipsig: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-4-22 a2f71b3 link true /test e2e-aws-4-22

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@cblecker

Copy link
Copy Markdown
Member

/retest-required

@hlipsig

hlipsig commented Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

/verified by @hlipsig

@openshift-ci-robot

Copy link
Copy Markdown

@hlipsig: This PR has been marked as verified by @hlipsig.

Details

In response to this:

/verified by @hlipsig

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@hlipsig

hlipsig commented Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-5.0

@openshift-cherrypick-robot

Copy link
Copy Markdown

@hlipsig: #9199 failed to apply on top of branch "release-5.0":

Applying: feat(api): add Azure Managed HSM support
Applying: chore(api): regenerate CRDs, clients, and vendor
Applying: feat(cli): configure Azure KMS vault type from key URLs
Applying: feat(hypershift-operator): support Azure Managed HSM endpoints
Using index info to reconstruct a base tree...
M	hypershift-operator/controllers/hostedcluster/hostedcluster_controller_test.go
M	support/azureutil/azureutil_test.go
Falling back to patching base and 3-way merge...
Auto-merging hypershift-operator/controllers/hostedcluster/hostedcluster_controller_test.go
Auto-merging support/azureutil/azureutil_test.go
CONFLICT (content): Merge conflict in support/azureutil/azureutil_test.go
error: Failed to merge in the changes.
hint: Use 'git am --show-current-patch=diff' to see the failed patch
hint: When you have resolved this problem, run "git am --continue".
hint: If you prefer to skip this patch, run "git am --skip" instead.
hint: To restore the original branch and stop patching, run "git am --abort".
hint: Disable this message with "git config set advice.mergeConflict false"
Patch failed at 0004 feat(hypershift-operator): support Azure Managed HSM endpoints

Details

In response to this:

/cherry-pick release-5.0

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

This branch was successfully deployed

1 active deployment
docs-preview/pr-9199 — d3ea9f64 Deployed Aug 20, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/documentation Indicates the PR includes changes for documentation area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/platform/azure PR/issue for Azure (AzurePlatform) platform area/testing Indicates the PR includes changes for e2e testing jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.