Repository navigation
[release-4.22] CNTRLPLANE-4024: feat(azure): support managed HSM for KMS encryption - #9437
Conversation
- Add AzureKMSKeyVaultType to AzureKMSSpec with backward-compatible immutability validation - Support Public, US Government, China, German, and Bleu Azure clouds - Accept Managed HSM encryption key URLs and regenerate feature-gated API manifests Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Regenerate install CRDs and validation suites for Managed HSM and sovereign clouds - Cover immutable vault type transitions and all supported Azure key URL suffixes - Update the AzureKMSSpec client and vendored HyperShift API types Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Propagate the detected vault type into AzureKMSSpec during cluster creation - Expose all supported Azure cloud environments in CLI help - Document Key Vault and Managed HSM encryption key URL formats Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Resolve Key Vault and Managed HSM endpoints across all supported Azure clouds - Preserve legacy Key Vault fingerprints while distinguishing Managed HSM keys - Gate Managed HSM on OpenShift 4.22 without masking release resolution failures Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Pass Managed HSM mode to both active and backup Azure KMS provider sidecars - Use one immutable vault type for active, backup, and rotation target keys - Preserve legacy Key Vault provider names while distinguishing Managed HSM providers Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Describe supported Azure KMS services, clouds, and minimum OpenShift version - Regenerate the API reference and aggregated documentation Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Commit-Message-Assisted-by: Claude (via Claude Code) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Regenerate feature-gated and install CRDs against the release-4.22 API set after resolving the backport conflicts. Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Port the Managed HSM sidecar flag and provider identity tests to the release-4.22 Azure KMS provider API. Signed-off-by: Hilliary Lipsig <hlipsig@redhat.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
@hlipsig: This pull request references CNTRLPLANE-4025 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target either version "4.22.0." or "openshift-4.22.0.", but it targets "openshift-5.0" instead. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## release-4.22 #9437 +/- ##
================================================
+ Coverage 36.53% 36.71% +0.18%
================================================
Files 777 777
Lines 95363 95484 +121
================================================
+ Hits 34840 35061 +221
+ Misses 57682 57580 -102
- Partials 2841 2843 +2
🚀 New features to boost your workflow:
|
|
/retitle [release-4.22] CNTRLPLANE-4024: feat(azure): support managed HSM for KMS encryption |
|
@hlipsig: This pull request references CNTRLPLANE-4024 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/pipeline required |
|
Scheduling tests matching the |
|
/lgtm |
|
Tests from second stage were triggered manually. Pipeline can be controlled only manually, until HEAD changes. Use command to trigger second stage. |
everettraven
left a comment
There was a problem hiding this comment.
Non-blocking note.
Other than that, this LGTM from an API perspective.
/approve for api
| // AzureKMSSpec defines metadata about the configuration of the Azure KMS Secret Encryption provider using Azure Key Vault or Managed HSM. | ||
| // | ||
| // +kubebuilder:validation:XValidation:rule="!has(self.backupKey) || self.backupKey.keyVaultName == self.activeKey.keyVaultName",message="backupKey.keyVaultName must match activeKey.keyVaultName; both keys must reside in the same Key Vault" | ||
| // +kubebuilder:validation:XValidation:rule="(has(self.keyVaultType) ? self.keyVaultType : 'KeyVault') == (has(oldSelf.keyVaultType) ? oldSelf.keyVaultType : 'KeyVault')",message="keyVaultType is immutable" |
There was a problem hiding this comment.
As a note, this rule is only enforceable if the parent field for this type - which appears to be optional - is not removed first.
If the parent field is removed, an end-user can re-apply a different configuration, circumventing this immutability constraint.
In order for true immutability, these types of rules need to be enforced at the highest parent field in the tree that is a required field.
I won't block on this as this has already merged previously, but we should at least make a note of needing to resolve this if we want true immutability here.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: bryan-cox, everettraven, hlipsig, jparrill The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/verified by @hlipsig |
|
/retest |
|
@hlipsig: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest |
1 similar comment
|
/retest |
|
/override ci/prow/e2e-aws-upgrade-hypershift-operator |
|
@csrwng: Overrode contexts on behalf of csrwng: ci/prow/e2e-aws-upgrade-hypershift-operator DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@hlipsig: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/label backport-risk-assessed |
3004374
into
openshift:release-4.22
Summary
Backport the complete contents of #9199 to
release-4.22, following the release-5.0 backport in #9376.This adds Azure Managed HSM support for KMS encryption across the API, generated CRDs and clients, CLI, HyperShift Operator, Control Plane Operator, key rotation, documentation, and setup tooling.
Manual conflict resolution
Release-4.22 predates several main-branch API and controller refactors, so conflicts were resolved by retaining the release branch architecture while applying the Managed HSM behavior:
keyVaultType.Validation
UPDATE=true make testmake verifygeneration, update, staticcheck, formatting, and vet targetsPYENV_VERSION=3.10.0 PULL_BASE_SHA=upstream/release-4.22 make -j verify-parallelmake verify-git-cleanReferences