OSAC-5618: Enable system tenant owned secrets - #1215
Conversation
|
@DakCrowder: This pull request references OSAC-5618 which is a valid jira issue. DetailsIn response to this: Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: osac-project/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (4)
💤 Files with no reviewable changes (2)
Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review. WalkthroughThe tenant reconciler now provisions Vault namespaces for the system tenant. The private Secret server applies platform authorization to system-tenant Secrets and requires Vault for their creation. ChangesSystem Tenant Platform Secrets
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Suggested labels: Suggested reviewers: Merge Risk: ⚪ Minimal · up to No concrete merge-blocking issue is established by the supplied evidence; normal validation can proceed. 🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Comment |
|
✅ E2E CaaS Full Install -- Passing Previously failing; now passing as of this run. ✅ E2E VMaaS Full Install -- Passing Previously failing; now passing as of this run. ⏳ E2E BMaaS Full Install -- Running Total AI diagnostic cost for this PR: $0.6787 (199134 input + 23372 output tokens across 6 diagnoses) |
🧭 Jobs Selection (informational only)E2E Suites
AI judgment confidence: 90%. Unit Tests
Integration Tests
Helm Lint
Checks & Builds
Every table above is informational only -- nothing here gates whether a job actually runs. The E2E Suites table can use AI judgment for ambiguous files; every other table is deterministic-only (no AI). |
E2E on CodeRabbit approvalCodeRabbit APPROVED — starting expensive e2e (PR run replay).
|
744fd60 to
80c3ab8
Compare
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: CrystalChun, DakCrowder The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
E2E on
|
d2781f6
In order to support future usecases from Cloud Provider Admins creating system level secrets, we should enable the system tenant to allow for creation of secrets by authorized users.
This defines no consumers, but seeks to unblock/enable them in the future.
Summary
Backward compatibility: System-tenant Secret operations that were previously denied can now succeed for authorized platform administrators. Secret creation for shared or system tenants now returns an error if the backend is not Vault or Vault is not configured.
Risk classification
Applied label: Unavailable. The supplied evidence does not identify a risk label applied to this change or provide criteria for
risk:ship,risk:show, orrisk:ask. No supported comparison with another classification is available.