New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update example values and KKPConfig to respect OIDC settings #8851
Update example values and KKPConfig to respect OIDC settings #8851
Conversation
There were a misleading steps in the example values around the configuration of dex clients and KKPConfiguration. Value of `issuerClientSecret` belongs to the issuer == used for accessing kubeconfig of user clusters via OIDC authentication. And thus is actually not needed if users don't use that option. It was discovered during the investigation of related issue - kubermatic#8723. Right now the situation was misleading because `issuerClientSecret` is not connected with the usage of `kubermatic` client (that is used for access KKP dahboard).
/assign @zreigz |
perfecto 👍 someone from app-management has to approve |
LGTM label has been added. Git tree hash: cb8acaea3bb415c7742751d38ac91efcf942acc3
|
/lgtm |
/retest |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/approve
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: michalvanco, xrstf The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
/retest Review the full test history Silence the bot with an |
/cherrypick release/v2.20 release/v2.19 |
@michalvanco: cannot checkout In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/cherrypick release/v2.20 |
@michalvanco: new pull request created: #8944 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/cherrypick release/v2.19 |
@michalvanco: new pull request created: #8945 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Based on the issue and update in kubermatic/kubermatic#8851.
What does this PR do / Why do we need it:
There were a misleading steps in the example values around the configuration of dex clients and KKPConfiguration.
Value of
issuerClientSecret
belongs to the issuer == used for accessing kubeconfig of user clusters via OIDC authentication.And thus is actually not needed if users don't use that option.
It was discovered during the investigation of related issue - #8723.
Right now the situation was misleading because
issuerClientSecret
is not connected with the usage ofkubermatic
client (that is used for access KKP dahboard).Does this PR close any issues?:
Fixes #
Special notes for your reviewer:
Documentation:
No updates in docs needed.
Does this PR introduce a user-facing change?: