Skip to content

Conversation

@wgabor0427
Copy link
Contributor

@wgabor0427 wgabor0427 commented Oct 30, 2025

@openshift-ci openshift-ci bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Oct 30, 2025
@ocpdocs-previewbot
Copy link

ocpdocs-previewbot commented Oct 30, 2025

Copy link

@bharath-b-rh bharath-b-rh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry I had missed few input in the shared draft, and added those as suggestions here.


Issued: 2025-11-03

The following advisories are available for the {external-secrets-operator} 0.1.0:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The following advisories are available for the {external-secrets-operator} 0.1.0:
The following advisories are available for the {external-secrets-operator} 1.0.0:

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

* link:https://access.redhat.com/errata/RHBA-2025:13134[RHBA-2025:13134]
* link:https://access.redhat.com/errata/RHBA-2025:13133[RHBA-2025:13133]

Version 1.0.0 of the {external-secrets-operator} is based on the upstream external-secrets version v0.19.0. For more information, see thelink:https://github.com/external-secrets/external-secrets/releases/tag/v0.19.0[external-secrets project release notes for v0.19.0].

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Version 1.0.0 of the {external-secrets-operator} is based on the upstream external-secrets version v0.19.0. For more information, see thelink:https://github.com/external-secrets/external-secrets/releases/tag/v0.19.0[external-secrets project release notes for v0.19.0].
Version 1.0.0 of the {external-secrets-operator} is based on the upstream external-secrets version v0.19.0. For more information, see the link:https://github.com/external-secrets/external-secrets/releases/tag/v0.19.0[external-secrets project release notes for v0.19.0].

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes aren't reflecting, please have a look.


*Renaming and improvements on the Operator API*

With this release, the Operator API `externalsecrets.operator.openshift.io`` has been renamed to `externalsecretsconfigs.operator.openshift.io`` to avoid confusions with the external-secrets provided API that has the same name, but a different purpose. The API has also been restructured and new features are added.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
With this release, the Operator API `externalsecrets.operator.openshift.io`` has been renamed to `externalsecretsconfigs.operator.openshift.io`` to avoid confusions with the external-secrets provided API that has the same name, but a different purpose. The API has also been restructured and new features are added.
With this release, the Operator API `externalsecrets.operator.openshift.io` has been renamed to `externalsecretsconfigs.operator.openshift.io` to avoid confusions with the external-secrets provided API that has the same name, but a different purpose. The API has also been restructured and new features are added.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


For more information, see {external-secrets-operator} APIs.

*Support to collect metrics of both operator and operands*

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Changed it from the initial input

Suggested change
*Support to collect metrics of both operator and operands*
*Support to collect metrics of External Secrets Operator components*

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

*Support to collect metrics of both operator and operands*

With this release, the {external-secrets-operator} supports collecting metrics for both the Operator and operands. This is optional and must be enabled.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
For more information, see Monitoring the External Secrets Operator for Red Hat OpenShift.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes aren't reflecting, please have a look.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


With this release, the {external-secrets-operator} supports collecting metrics for both the Operator and operands. This is optional and must be enabled.

*Support to configure proxy*

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*Support to configure proxy*
*Support to configure proxy for External Secrets Operator components*

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


For more information, see About the egress proxy for the {external-secrets-operator}.


Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
*Root filesystem is read-only for External Secrets Operator for Red Hat OpenShift containers*
With this release, to improve security, the External Secrets Operator for Red Hat OpenShift and all its operands have the readOnlyRootFilesystem security context set to true by default. This enhancement hardens the containers and prevents a potential attacker from modifying the contents of the container’s root file system.
*Network policy hardening is now available for External Secrets Operator components*
With this release, External Secrets Operator for Red Hat OpenShift includes pre-defined NetworkPolicy resources designed for enhanced security by governing ingress and egress traffic for operand components. These policies cover essential internal traffic, such as ingress to the metrics and webhook servers, and egress to the OpenShift API server and DNS server. Note that deployment of the NetworkPolicy is enabled by default and egress allow policies must be explicitly defined in the ExternalSecretsConfig custom resource for the external-secrets component to fetch secrets from external providers.
For more information, see Configuring Network Policy for the Operands.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Comment on lines 22 to 24
* link:https://access.redhat.com/errata/RHBA-2025:13182[RHBA-2025:13182]
* link:https://access.redhat.com/errata/RHBA-2025:13134[RHBA-2025:13134]
* link:https://access.redhat.com/errata/RHBA-2025:13133[RHBA-2025:13133]

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The advisories are now available.

Suggested change
* link:https://access.redhat.com/errata/RHBA-2025:13182[RHBA-2025:13182]
* link:https://access.redhat.com/errata/RHBA-2025:13134[RHBA-2025:13134]
* link:https://access.redhat.com/errata/RHBA-2025:13133[RHBA-2025:13133]
* link:https://access.redhat.com/errata/RHBA-2025:19416[RHBA-2025:19416]
* link:https://access.redhat.com/errata/RHBA-2025:19417[RHBA-2025:19417]
* link:https://access.redhat.com/errata/RHBA-2025:19418[RHBA-2025:19418]
* link:https://access.redhat.com/errata/RHBA-2025:19463[RHBA-2025:19463]

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

@wgabor0427 wgabor0427 force-pushed the OSDOCS-17030 branch 3 times, most recently from 04653fe to 902f13b Compare November 3, 2025 14:35
@openshift-ci
Copy link

openshift-ci bot commented Nov 3, 2025

@wgabor0427: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Copy link

@bharath-b-rh bharath-b-rh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Nov 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm Indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants