Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
labels:
authentication.openshift.io/csr: openshift-authenticator
spec:
request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkRUQ0J0QUlCQURCU01WQXdUZ1lEVlFRREUwZHplWE4wWlcwNmMyVnlkbWxqWldGalkyOTFiblE2YjNCbApibk5vYVdaMExXOWhkWFJvTFdGd2FYTmxjblpsY2pwdmNHVnVjMmhwWm5RdFlYVjBhR1Z1ZEdsallYUnZjakJaCk1CTUdCeXFHU000OUFnRUdDQ3FHU000OUF3RUhBMElBQk1RUkx4S1BYZklJZHFYQUlMcmpidHNJRmVTZDRPQW8KNFFZbFAvWGlTTEVpNnJydWRCa2xuVVl1UTM3N2g4Mnh0Vk43QnhLUUkxVWFYeDg2R3hreFgwNmdBREFLQmdncQpoa2pPUFFRREFnTklBREJGQWlBVGUwZjMyQStJa2NSS0djN25zU2dRaytCVXRQejlyWU55TVljNmN2Q3A0QUloCkFOdVI2TFhmcXBOYUYyYTBadzNzdWV0Vms5dElUaXQ3WXlWeE1Ka2dtSHhyCi0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo=
request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkREQ0J0QUlCQURCU01WQXdUZ1lEVlFRREUwZHplWE4wWlcwNmMyVnlkbWxqWldGalkyOTFiblE2YjNCbApibk5vYVdaMExXOWhkWFJvTFdGd2FYTmxjblpsY2pwdmNHVnVjMmhwWm5RdFlYVjBhR1Z1ZEdsallYUnZjakJaCk1CTUdCeXFHU000OUFnRUdDQ3FHU000OUF3RUhBMElBQkxrK2xGVG9CT2dGTDNjY0tKRXh2SmVOUXJLbGg0MVIKN0E2Qzk3eDFta0ZJY2NkWUEzTVNPRkdObkNURzRTNjBKUzJsWndDREJneFpPZkllT0R5TXlrbWdBREFLQmdncQpoa2pPUFFRREFnTkhBREJFQWlBbmJmQ3pzSFZHRlF2ak5Oemh1VFd2dFJXUXZiT0lQZnkvRUNRZnBWZldyd0lnClNEZXh5UGFsM1A2WnhNU21qN1dsSnEySlZac3dranA0ckpaempTRlFON3c9Ci0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo=
signerName: kubernetes.io/kube-apiserver-client
usages:
- digital signature
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
apiVersion: operator.openshift.io/v1
kind: Authentication
metadata:
name: cluster
status:
conditions:
- lastTransitionTime: "2025-08-07T22:38:20Z"
status: "False"
type: OAuthServerConfigObservationDegraded
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: ApplyStatus
controllerInstanceName: TODO-configObserver
fieldManager: oauth-server-ConfigObserver
generateName: ""
name: cluster
resourceType:
Group: operator.openshift.io
Resource: authentications
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
fieldManager: oauth-server-ConfigObserver
force: true
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: 'Writing updated section ("oauthServer") of observed config: "\u00a0\u00a0map[string]any{\n+\u00a0\t\"corsAllowedOrigins\":
[]any{string(`//127\\.0\\.0\\.1(:|$)`), string(\"//localhost(:|$)\")},\n+\u00a0\t\"oauthConfig\":
map[string]any{\n+\u00a0\t\t\"assetPublicURL\": string(\"https://console-openshift-console.apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX\"),\n+\u00a0\t\t\"loginURL\": string(\"https://api.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX:6443\"),\n+\u00a0\t\t\"tokenConfig\":
map[string]any{\n+\u00a0\t\t\t\"accessTokenMaxAgeSeconds\": float64(86400),\n+\u00a0\t\t\t\"authorizeTokenMaxAgeSeconds\":
float64(300),\n+\u00a0\t\t},\n+\u00a0\t},\n-\u00a0\t\"serverArguments\": nil,\n+\u00a0\t\"serverArguments\":
map[string]any{\n+\u00a0\t\t\"audit-log-format\": []any{string(\"json\")},\n+\u00a0\t\t\"audit-log-maxbackup\":
[]any{string(\"10\")},\n+\u00a0\t\t\"audit-log-maxsize\": []any{string(\"100\")},\n+\u00a0\t\t\"audit-log-path\": []any{string(\"/var/log/oauth-server/audit.log\")},\n+\u00a0\t\t\"audit-policy-file\": []any{string(\"/var/run/configmaps/audit/audit.yaml\")},\n+\u00a0\t},\n+\u00a0\t\"servingInfo\":
map[string]any{\n+\u00a0\t\t\"cipherSuites\": []any{\n+\u00a0\t\t\tstring(\"TLS_AES_128_GCM_SHA256\"),
string(\"TLS_AES_256_GCM_SHA384\"),\n+\u00a0\t\t\tstring(\"TLS_CHACHA20_POLY1305_SHA256\"),\n+\u00a0\t\t\tstring(\"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\"),\n+\u00a0\t\t\tstring(\"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\"),\n+\u00a0\t\t\tstring(\"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\"),\n+\u00a0\t\t\tstring(\"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\"),\n+\u00a0\t\t\tstring(\"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256\"),
...,\n+\u00a0\t\t},\n+\u00a0\t\t\"minTLSVersion\": string(\"VersionTLS12\"),\n+\u00a0\t\t\"namedCertificates\":
[]any{\n+\u00a0\t\t\tmap[string]any{\n+\u00a0\t\t\t\t\"certFile\": string(\"/var/config/system/secrets/v4-0-\"...),\n+\u00a0\t\t\t\t\"keyFile\": string(\"/var/config/system/secrets/v4-0-\"...),\n+\u00a0\t\t\t\t\"names\": []any{...},\n+\u00a0\t\t\t},\n+\u00a0\t\t},\n+\u00a0\t},\n+\u00a0\t\"volumesToMount\":
map[string]any{\"identityProviders\": string(\"{}\")},\n\u00a0\u00a0}\n"'
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.5f2cc1a1
namespace: openshift-authentication-operator
reason: ObservedConfigChanged
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.5f2cc1a1
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: assetPublicURL changed from to https://console-openshift-console.apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.6182ed8c
namespace: openshift-authentication-operator
reason: ObserveConsoleURL
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.6182ed8c
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: loginURL changed from to https://api.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX:6443
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.1d05f9ac
namespace: openshift-authentication-operator
reason: ObserveAPIServerURL
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.1d05f9ac
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: namedCertificates changed to []interface {}{map[string]interface {}{"certFile":"/var/config/system/secrets/v4-0-config-system-router-certs/apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX",
"keyFile":"/var/config/system/secrets/v4-0-config-system-router-certs/apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX",
"names":[]interface {}{"*.apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX"}}}
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.6d9ca9b2
namespace: openshift-authentication-operator
reason: ObserveRouterSecret
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.6d9ca9b2
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: minTLSVersion changed to VersionTLS12
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.44a05c38
namespace: openshift-authentication-operator
reason: ObserveTLSSecurityProfile
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.44a05c38
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: AuditProfile changed from '%!s(<nil>)' to 'map[audit-log-format:[json] audit-log-maxbackup:[10]
audit-log-maxsize:[100] audit-log-path:[/var/log/oauth-server/audit.log] audit-policy-file:[/var/run/configmaps/audit/audit.yaml]]'
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.a8ecfbce
namespace: openshift-authentication-operator
reason: ObserveAuditProfile
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.a8ecfbce
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: cipherSuites changed to ["TLS_AES_128_GCM_SHA256" "TLS_AES_256_GCM_SHA384"
"TLS_CHACHA20_POLY1305_SHA256" "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256" "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384" "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256" "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"]
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.49fb0e36
namespace: openshift-authentication-operator
reason: ObserveTLSSecurityProfile
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.49fb0e36
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
apiVersion: v1
count: 1
eventTime: null
firstTimestamp: "2025-08-07T22:38:20Z"
involvedObject:
kind: Deployment
name: authentication-operator
namespace: openshift-authentication-operator
kind: Event
lastTimestamp: "2025-08-07T22:38:20Z"
message: accessTokenMaxAgeSeconds changed from %!d(float64=0) to %!d(float64=86400)
metadata:
creationTimestamp: null
name: authentication-operator.18599d2230299800.2df24af9
namespace: openshift-authentication-operator
reason: ObserveTokenConfig
reportingComponent: ""
reportingInstance: ""
source:
component: cluster-authentication-operator-run-once-sync-context
type: Normal
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
action: Create
controllerInstanceName: ""
generateName: ""
name: authentication-operator.18599d2230299800.2df24af9
namespace: openshift-authentication-operator
resourceType:
Group: ""
Resource: events
Version: v1
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
apiVersion: operator.openshift.io/v1
kind: Authentication
metadata:
annotations:
include.release.openshift.io/self-managed-high-availability: "true"
include.release.openshift.io/single-node-developer: "true"
release.openshift.io/create-only: "true"
name: cluster
spec:
managementState: Managed
observedConfig:
oauthServer:
corsAllowedOrigins:
- //127\.0\.0\.1(:|$)
- //localhost(:|$)
oauthConfig:
assetPublicURL: https://console-openshift-console.apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX
loginURL: https://api.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX:6443
tokenConfig:
accessTokenMaxAgeSeconds: 86400
authorizeTokenMaxAgeSeconds: 300
serverArguments:
audit-log-format:
- json
audit-log-maxbackup:
- "10"
audit-log-maxsize:
- "100"
audit-log-path:
- /var/log/oauth-server/audit.log
audit-policy-file:
- /var/run/configmaps/audit/audit.yaml
servingInfo:
cipherSuites:
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
minTLSVersion: VersionTLS12
namedCertificates:
- certFile: /var/config/system/secrets/v4-0-config-system-router-certs/apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX
keyFile: /var/config/system/secrets/v4-0-config-system-router-certs/apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX
names:
- '*.apps.ci-op-gn2pz6q7-69aee.XXXXXXXXXXXXXXXXXXXXXX'
volumesToMount:
identityProviders: '{}'
unsupportedConfigOverrides: null
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
action: Update
controllerInstanceName: TODO-configObserver
generateName: ""
name: cluster
resourceType:
Group: operator.openshift.io
Resource: authentications
Version: v1
Loading