OCPBUGS-105321: pki: switch to ECDSA defaults and thread PKI profile to leaf certs - #10743
OCPBUGS-105321: pki: switch to ECDSA defaults and thread PKI profile to leaf certs#10743sanchezl wants to merge 7 commits into
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
📝 WalkthroughWalkthroughChangesConfigurable PKI now flows from effective profiles through Configurable PKI integration
Estimated code review effort: 4 (Complex) | ~60 minutes 🚥 Pre-merge checks | ✅ 14 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 golangci-lint (2.12.2)Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions Comment |
|
Skipping CI for Draft Pull Request. |
|
/test all |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
06ad91c to
9f4aa80
Compare
|
/test all |
|
/pipeline required |
|
Scheduling required tests: Scheduling tests matching the |
9f4aa80 to
65df21c
Compare
|
/test all |
|
/pipeline required |
|
Scheduling required tests: Scheduling tests matching the |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-10-techpreview |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f047f400-914e-11f1-8e35-4bb42ad1a5c4-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f1dfab00-914e-11f1-83c2-8d141c46cd05-0 |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-10-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f3b02540-914e-11f1-86a2-b0b4d2ce1f86-0 |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-fips |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f554fba0-914e-11f1-82cf-c1f8829a801b-0 |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-aws-ovn-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f745a810-914e-11f1-9a6b-7a95cb0904d2-0 |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-single-node-techpreview |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/f8b11ef0-914e-11f1-90de-25ab253cf8e2-0 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-usgov-ipi-custom-dns-mini-perm-tp-f7 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-c2s-ipi-disc-priv-fips-f28-tp-longduration-cloud |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-vsphere-short-cert-rotation-f7 |
|
/test e2e-aws-ovn |
|
@sanchezl: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/retest |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-upgrade-fips-rhcos9-10-techpreview |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-techpreview |
|
/payload-job e2e-metal-ipi-ovn-upgrade-rhcos9-10-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-fips |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-aws-ovn-techpreview |
|
/payload-job periodic-ci-openshift-release-main-nightly-5.0-e2e-aws-ovn-single-node-techpreview |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-usgov-ipi-custom-dns-mini-perm-tp-f7 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-aws-c2s-ipi-disc-priv-fips-f28-tp-longduration-cloud |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-vsphere-short-cert-rotation-f7 |
|
/payload-job periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-vsphere-ipi-proxy-fips-regen-cert-f14 |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-gcp-ovn-rhcos10-fips-techpreview-serial-1of2 |
|
/payload-job periodic-ci-openshift-release-main-ci-5.0-e2e-gcp-ovn-rhcos10-fips-techpreview-serial-2of2 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/cacb8f00-9290-11f1-8487-cf3a1805c877-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/cc444c50-9290-11f1-9665-04dd09631bb0-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d2bca3c0-9290-11f1-93a9-ea984056802f-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/bb4fc870-9290-11f1-880f-d771e4579bed-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/c69a1a50-9290-11f1-975a-d2e2f14e9831-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/bf6ccac0-9290-11f1-9e4d-6d96c80d7ffc-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/c8ef7c00-9290-11f1-94d0-692d5cbb577d-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/ce51a880-9290-11f1-8534-9d3be7d1c4e2-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/c1165c10-9290-11f1-925b-81da9ff1cfcf-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/c365ca50-9290-11f1-9b7e-dc981939baf2-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/bd6b7c80-9290-11f1-8dd1-93b85b95cdd7-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/d09f4200-9290-11f1-9196-c620fcae606f-0 |
|
@sanchezl: trigger 1 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command
See details on https://pr-payload-tests.ci.openshift.org/runs/ci/c4dc16a0-9290-11f1-8f47-a0fd447535ac-0 |
Why
When ConfigurablePKI is enabled, the installer's
DefaultPKIProfile()returns a hardcoded RSA-4096 placeholder instead of library-go's defaults (ECDSA P-256 / P-384). Leaf certs also ignore the PKI profile entirely and always generate RSA-2048. This diverges from what day-2 operators (CKAO, CKMO) expect when they read the PKI CR for certificate rotation.What
DefaultPKIProfile()with library-go's versionSignerKeyParamsto carry a fullPKIProfile+ConfigurablePKIEnabledResolveCertificateConfigWhy this is safe
Zero blast radius for default installs. Every cert asset has a clear feature-gate guard:
When the feature gate is off (all production installs today), the existing hand-rolled crypto runs unchanged. The new library-go path only executes under TechPreview/CustomNoUpgrade with ConfigurablePKI explicitly enabled.
Agent flow preserved.
SignerKeyParamsremains zero-dependency —agent create certificatescontinues to work without install-config on disk, generating RSA-2048 certs via the legacy path. This pattern was established in PR #10595 after review by zaneb, tthvo, and andfasano (see PR #10595 discussion).Easy to cull. When ConfigurablePKI is promoted to always-on, the legacy branches and the old
GenerateSignedCertificate()/PrivateKey()functions can be deleted in one sweep. No behavioral dependencies between the two paths.Design decisions from prior PRs
This PR builds on the stacked PRs #10594 and #10595 (both merged). Key decisions inherited:
SignerKeyParams(PR CNTRLPLANE-2012: Wire signer certs to read PKI config via SignerKeyParams #10595, zaneb's review): avoids pulling InstallConfig validation into agent flowsAssetBase.LoadFromFile(PR CNTRLPLANE-2012: Wire signer certs to read PKI config via SignerKeyParams #10595, tthvo's feedback): strict YAML parsing without platform validationSignerKeyParamsinManifestsandagentManifestsTargetfor multi-step state persistenceagentCertificatesTarget(PR CNTRLPLANE-2012: Wire signer certs to read PKI config via SignerKeyParams #10595, zaneb): "install-config is not an input to this command"Commit walkthrough
The commits are ordered to build incrementally:
vendor: bump library-go— vendor-only, no functional changespki: replace local DefaultPKIProfile with library-go—pkg/types/pki/defaults.goonly, smallpki: extend SignerKeyParams—signerkey_params.go+ all signer asset dependency updatestls: add resolveKeyGen helpers— single new file, 24 linestls: add library-go code path to SelfSignedCertKey and SignedCertKey— core engine change incertkey.gotls: wire feature-gate branches— bulk mechanical change, same pattern in every cert assettls: fix cert types for library-go path— JournalCertKey → Peer (serves HTTPS and authenticates curl client with same cert), AdminKubeConfigClientCertKey → Client only (drops legacy ServerAuth — verified on live cluster including localhost-recovery), dead code removalCommit 6 is the largest but entirely mechanical — each asset follows the same pattern from commit 5. Review one asset (e.g.,
root.go) and spot-check the rest.Test plan
hack/build.sh)agent create certificatesintegration test passes without install-configSummary by CodeRabbit