-
Notifications
You must be signed in to change notification settings - Fork 521
SPIRE-211: add SPIRE federation support in ZTWIM #1863
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
@rausingh-rh: This pull request references SPIRE-211 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Skipping CI for Draft Pull Request. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
91784f2 to
35cafb8
Compare
35cafb8 to
756d833
Compare
|
@rausingh-rh: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
This PR adds native support for SPIRE Federation in the Zero Trust Workload Identity Manager operator, enabling secure cross-cluster workload communication. The operator will manage federation endpoints, automate trust bundle exchange, and support federation between N clusters (where N is limited to a configurable maximum, default 10 clusters per trust domain).
Currently, federation setup is a manual multi-step process requiring direct ConfigMap manipulation, manual trust bundle extraction, and route creation. This enhancement automates the entire federation lifecycle through declarative API configuration.