cloud-provider icon indicating copy to clipboard operation
cloud-provider copied to clipboard

Extracting/Migrating the Credential Provider: KEP + Alpha Implementation

Open andrewsykim opened this issue 6 years ago • 14 comments

As part of the cloud provider extraction/migration, we should start to look into how the credential provider is going to be extracted so that the kubelet does not rely on cloud SDKs for image pulling credentials. Also to support future credential providers without adding it into the main tree.

Need to work with SIG Auth and propose a KEP to extract/migrate credential providers to move out-of-tree.

related: https://github.com/kubernetes/kubernetes/issues/68810

cc @justinsb @mcrute

andrewsykim avatar Feb 21 '19 16:02 andrewsykim

/assign @mcrute

mcrute avatar Feb 23 '19 05:02 mcrute

Also related kubernetes/kubernetes#70675

mcrute avatar Feb 23 '19 05:02 mcrute

@mcrute and I are doodling out some ideas for this, hoping we can have an alpha feature-gated version of this in for v1.15.

cc @liggitt @smarterclayton

andrewsykim avatar Mar 01 '19 19:03 andrewsykim

Would secret a possible solution for this?

feiskyer avatar Mar 20 '19 06:03 feiskyer

Would secret a possible solution for this?

Yes, this is one of the possible solutions we're discussing. KEP is work in progress :)

andrewsykim avatar Mar 20 '19 17:03 andrewsykim

/milestone v1.15 /priority critical-urgent

cc @dchen1107 @derekwaynecarr

andrewsykim avatar Mar 20 '19 20:03 andrewsykim

For v1.15, p0: KEP + alpha implementation

andrewsykim avatar Mar 28 '19 19:03 andrewsykim

Rough draft of the KEP, mostly just the problem statement at this point.

mcrute avatar Apr 11 '19 02:04 mcrute

For v1.15, p0: KEP + alpha implementation

@andrewsykim What's your proposal for alpha implementation?

feiskyer avatar Apr 11 '19 07:04 feiskyer

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale. Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Send feedback to sig-testing, kubernetes/test-infra and/or fejta. /lifecycle stale

fejta-bot avatar Sep 10 '19 20:09 fejta-bot

/remove-lifecycle stale

andrewsykim avatar Sep 11 '19 17:09 andrewsykim

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale. Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Send feedback to sig-testing, kubernetes/test-infra and/or fejta. /lifecycle stale

fejta-bot avatar Dec 31 '19 21:12 fejta-bot

/remove-lifecycle stale

cheftako avatar Jan 02 '20 23:01 cheftako

/lifecycle frozen

cheftako avatar Jan 02 '20 23:01 cheftako