Repository navigation
[release-5.0] CNTRLPLANE-4025: feat(azure): support managed HSM for KMS encryption - #9376
Conversation
- Add AzureKMSKeyVaultType to AzureKMSSpec with backward-compatible immutability validation - Support Public, US Government, China, German, and Bleu Azure clouds - Accept Managed HSM encryption key URLs and regenerate feature-gated API manifests Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Regenerate install CRDs and validation suites for Managed HSM and sovereign clouds - Cover immutable vault type transitions and all supported Azure key URL suffixes - Update the AzureKMSSpec client and vendored HyperShift API types Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Propagate the detected vault type into AzureKMSSpec during cluster creation - Expose all supported Azure cloud environments in CLI help - Document Key Vault and Managed HSM encryption key URL formats Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Resolve Key Vault and Managed HSM endpoints across all supported Azure clouds - Preserve legacy Key Vault fingerprints while distinguishing Managed HSM keys - Gate Managed HSM on OpenShift 4.22 without masking release resolution failures Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Pass Managed HSM mode to both active and backup Azure KMS provider sidecars - Use one immutable vault type for active, backup, and rotation target keys - Preserve legacy Key Vault provider names while distinguishing Managed HSM providers Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Describe supported Azure KMS services, clouds, and minimum OpenShift version - Regenerate the API reference and aggregated documentation Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
@hlipsig: This pull request references CNTRLPLANE-4025 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/label backport-risk-assessed |
|
@hlipsig: The label(s) DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/verified by @hlipsig |
|
@hlipsig: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: bryan-cox, hlipsig The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/lgtm |
|
Scheduling tests matching the |
|
/retest |
|
/retest |
2 similar comments
|
/retest |
|
/retest |
|
/test e2e-kubevirt-aws-ovn-reduced |
|
/override "e2e-kubevirt-aws-ovn-reduced" |
|
@bryan-cox: /override requires failed status contexts, check run or a prowjob name to operate on.
Only the following failed contexts/checkruns were expected:
If you are trying to override a checkrun that has a space in it, you must put a double quote on the context. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override "ci/prow/e2e-kubevirt-aws-ovn-reduced" |
|
@bryan-cox: Overrode contexts on behalf of bryan-cox: ci/prow/e2e-kubevirt-aws-ovn-reduced DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override "ci/prow/e2e-kubevirt-aws-ovn-reduced" |
|
@bryan-cox: Overrode contexts on behalf of bryan-cox: ci/prow/e2e-kubevirt-aws-ovn-reduced DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@hlipsig: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
c94b15c
into
openshift:release-5.0
Summary
Backport the complete contents of #9199 to
release-5.0.This adds Azure Managed HSM support for KMS encryption across the API, generated CRDs and clients, CLI, HyperShift Operator, Control Plane Operator, key rotation, documentation, and setup tooling.
Manual conflict resolution
Two test-only conflicts caused by release-5.0 drift were resolved by retaining the release branch context and adding the Managed HSM test coverage from the original PR:
support/azureutil/azureutil_test.gocontrol-plane-operator/controllers/hostedcontrolplane/v2/kas/kms_test.goValidation
make run-gitlintpasses.make verifyreaches the CRD compatibility check and reports pre-existing AWS resource-tag regex changes already present onupstream/release-5.0, including in files untouched by this backport.References