compliance-operator icon indicating copy to clipboard operation
compliance-operator copied to clipboard

Remove certificate secrets after compliance scan is done

Open bukovjanmic opened this issue 1 year ago • 0 comments

Currently, there is a number of certificates generated for a compliance scan, which have 1 day validity.

After the scan is done, the certificate secrets are left and only deleted/replaced before next scan.

On the cluster, we have cert-utils-operators, which guards against expired certificates. Thus, a number of alerts is generated for each such certificate, as all certificates expire before new ones are generated.

Since the certificates does not seem to be used after the compliance scan is done anymore, would it be possible to remove them once they are not needed anymore?

bukovjanmic avatar Apr 14 '23 10:04 bukovjanmic