Skip to content

Commit 7432dbb

Browse files
committed
Adding the Security HCP cherrypick
1 parent 34c5b84 commit 7432dbb

36 files changed

+613
-26
lines changed

.s2i/httpd-cfg/01-commercial.conf

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -386,7 +386,11 @@ AddType text/vtt vtt
386386

387387
# Service Mesh landing page
388388

389+
<<<<<<< HEAD
389390
RewriteRule ^container-platform/(4\.14|4\.15|4\.16|4\.17|4\.18)/service_mesh/v3x/ossm-service-mesh-3-0-overview.html /service-mesh/3.0.0tp1/about/ossm-about-openshift-service-mesh.html [NE,R=302]
391+
=======
392+
RewriteRule ^container-platform/(4\.9|4\.10|4\.11|4\.12|4\.13|4\.14|4\.15|4\.16|4\.17|4\.18)/service-mesh/about/ossm-about-openshift-service-mesh.html /service-mesh/latest/about/ossm-about-openshift-service-mesh.html [NE,R=302]
393+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
390394

391395
# Pipelines handling unversioned and latest links
392396
RewriteRule ^pipelines/?$ /pipelines/latest [R=302]

_attributes/common-attributes.adoc

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,8 +40,11 @@ endif::[]
4040
:oadp-full: OpenShift API for Data Protection
4141
:oadp-short: OADP
4242
:oadp-version: 1.4.1
43+
<<<<<<< HEAD
4344
:oadp-version-1-3: 1.3.3
4445
:oadp-version-1-4: 1.4.1
46+
=======
47+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
4548
:oc-first: pass:quotes[OpenShift CLI (`oc`)]
4649
:product-registry: OpenShift image registry
4750
:product-mirror-registry: Mirror registry for Red Hat OpenShift

_topic_maps/_topic_map.yml

Lines changed: 22 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -135,22 +135,22 @@ Topics:
135135
- Name: Updating a cluster in a disconnected environment
136136
Dir: updating
137137
Topics:
138-
- Name: About cluster updates in a disconnected environment
139-
File: index
140-
- Name: Mirroring OpenShift Container Platform images
141-
File: mirroring-image-repository
142-
- Name: Updating a cluster in a disconnected environment using OSUS
143-
File: disconnected-update-osus
144-
Distros: openshift-enterprise
145-
- Name: Updating a cluster in a disconnected environment without OSUS
146-
File: disconnected-update
147-
Distros: openshift-enterprise
148-
- Name: Updating a cluster in a disconnected environment by using the CLI
149-
File: disconnected-update
150-
Distros: openshift-origin
151-
- Name: Uninstalling OSUS from a cluster
152-
File: uninstalling-osus
153-
Distros: openshift-enterprise
138+
- Name: About cluster updates in a disconnected environment
139+
File: index
140+
- Name: Mirroring OpenShift Container Platform images
141+
File: mirroring-image-repository
142+
- Name: Updating a cluster in a disconnected environment using OSUS
143+
File: disconnected-update-osus
144+
Distros: openshift-enterprise
145+
- Name: Updating a cluster in a disconnected environment without OSUS
146+
File: disconnected-update
147+
Distros: openshift-enterprise
148+
- Name: Updating a cluster in a disconnected environment by using the CLI
149+
File: disconnected-update
150+
Distros: openshift-origin
151+
- Name: Uninstalling OSUS from a cluster
152+
File: uninstalling-osus
153+
Distros: openshift-enterprise
154154
---
155155
Name: Installing
156156
Dir: installing
@@ -2522,11 +2522,17 @@ Topics:
25222522
File: hcp-destroy-virt
25232523
- Name: Destroying a hosted cluster on IBM Z
25242524
File: hcp-destroy-ibmz
2525+
<<<<<<< HEAD
25252526
- Name: Destroying a hosted cluster on IBM Power
25262527
File: hcp-destroy-ibmpower
25272528
- Name: Destroying a hosted cluster on non-bare metal agent machines
25282529
File: hcp-destroy-non-bm
25292530
- Name: Manually importing a hosted cluster
2531+
=======
2532+
- Name: Destroying a hosted cluster on non-bare metal agent machines
2533+
File: hcp-destroy-non-bm
2534+
- Name: Manually importing a hosted control plane cluster
2535+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
25302536
File: hcp-import
25312537
---
25322538
Name: Nodes

_topic_maps/_topic_map_ms.yml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,8 +33,13 @@ Name: Red Hat build of MicroShift release notes
3333
Dir: microshift_release_notes
3434
Distros: microshift
3535
Topics:
36+
<<<<<<< HEAD
3637
- Name: Red Hat build of MicroShift 4.18 release notes
3738
File: microshift-4-18-release-notes
39+
=======
40+
- Name: Red Hat build of MicroShift 4.17 release notes
41+
File: microshift-4-17-release-notes
42+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
3843
---
3944
Name: Getting ready to install MicroShift
4045
Dir: microshift_install_get_ready
@@ -110,7 +115,11 @@ Dir: microshift_configuring
110115
Distros: microshift
111116
Topics:
112117
- Name: Using the MicroShift configuration file
118+
<<<<<<< HEAD
113119
File: microshift-using-config-yaml
120+
=======
121+
File: microshift-using-config-tools
122+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
114123
- Name: Configuring IPv6 networking
115124
File: microshift-nw-ipv6-config
116125
- Name: Cluster access with kubeconfig
@@ -121,8 +130,11 @@ Topics:
121130
File: microshift-greenboot-checking-status
122131
- Name: Configuring audit logging policies
123132
File: microshift-audit-logs-config
133+
<<<<<<< HEAD
124134
- Name: Disabling LVMS CSI provider and CSI snapshot
125135
File: microshift-disable-lvms-csi-provider-csi-snapshot
136+
=======
137+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
126138
- Name: Configuring low latency
127139
Dir: microshift_low_latency
128140
Topics:

_topic_maps/_topic_map_rosa_hcp.yml

Lines changed: 84 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -576,6 +576,90 @@ Distros: openshift-rosa-hcp
576576
Topics:
577577
- Name: Adding additional constraints for IP-based AWS role assumption
578578
File: rosa-adding-additional-constraints-for-ip-based-aws-role-assumption
579+
# ---
580+
# - Name: Security
581+
# File: rosa-security
582+
# - Name: Application and cluster compliance
583+
# File: rosa-app-security-compliance
584+
# ---
585+
# Name: Authentication and authorization
586+
# Dir: authentication
587+
# Distros: openshift-rosa-hcp
588+
# Topics:
589+
# - Name: Authentication and authorization overview
590+
# File: index
591+
# - Name: Understanding authentication
592+
# File: understanding-authentication
593+
# - Name: Configuring the internal OAuth server
594+
# File: configuring-internal-oauth
595+
# - Name: Configuring OAuth clients
596+
# File: configuring-oauth-clients
597+
# - Name: Managing user-owned OAuth access tokens
598+
# File: managing-oauth-access-tokens
599+
# - Name: Understanding identity provider configuration
600+
# File: understanding-identity-provider
601+
# - Name: Configuring identity providers
602+
# File: sd-configuring-identity-providers
603+
# - Name: Configuring identity providers
604+
# Dir: identity_providers
605+
# Topics:
606+
# - Name: Configuring an htpasswd identity provider
607+
# File: configuring-htpasswd-identity-provider
608+
# - Name: Configuring a Keystone identity provider
609+
# File: configuring-keystone-identity-provider
610+
# - Name: Configuring an LDAP identity provider
611+
# File: configuring-ldap-identity-provider
612+
# - Name: Configuring a basic authentication identity provider
613+
# File: configuring-basic-authentication-identity-provider
614+
# - Name: Configuring a request header identity provider
615+
# File: configuring-request-header-identity-provider
616+
# - Name: Configuring a GitHub or GitHub Enterprise identity provider
617+
# File: configuring-github-identity-provider
618+
# - Name: Configuring a GitLab identity provider
619+
# File: configuring-gitlab-identity-provider
620+
# - Name: Configuring a Google identity provider
621+
# File: configuring-google-identity-provider
622+
# - Name: Configuring an OpenID Connect identity provider
623+
# File: configuring-oidc-identity-provider
624+
# - Name: Using RBAC to define and apply permissions
625+
# File: using-rbac
626+
# - Name: Removing the kubeadmin user
627+
# File: remove-kubeadmin
628+
# - Name: Configuring LDAP failover
629+
# File: configuring-ldap-failover
630+
# - Name: Understanding and creating service accounts
631+
# File: understanding-and-creating-service-accounts
632+
# - Name: Using service accounts in applications
633+
# File: using-service-accounts-in-applications
634+
# - Name: Using a service account as an OAuth client
635+
# File: using-service-accounts-as-oauth-client
636+
# - Name: Assuming an AWS IAM role for a service account
637+
# File: assuming-an-aws-iam-role-for-a-service-account
638+
# - Name: Scoping tokens
639+
# File: tokens-scoping
640+
# - Name: Using bound service account tokens
641+
# File: bound-service-account-tokens
642+
# - Name: Managing security context constraints
643+
# File: managing-security-context-constraints
644+
# - Name: Understanding and managing pod security admission
645+
# File: understanding-and-managing-pod-security-admission
646+
# - Name: Impersonating the system:admin user
647+
# File: impersonating-system-admin
648+
# - Name: Syncing LDAP groups
649+
# File: ldap-syncing
650+
# - Name: Managing cloud provider credentials
651+
# Dir: managing_cloud_provider_credentials
652+
# Topics:
653+
# - Name: About the Cloud Credential Operator
654+
# File: about-cloud-credential-operator
655+
# - Name: Mint mode
656+
# File: cco-mode-mint
657+
# - Name: Passthrough mode
658+
# File: cco-mode-passthrough
659+
# - Name: Manual mode with long-term credentials for components
660+
# File: cco-mode-manual
661+
# - Name: Manual mode with short-term credentials for components
662+
# File: cco-short-term-creds
579663
---
580664
# ---
581665
# Name: Authentication and authorization

backup_and_restore/application_backup_and_restore/release-notes/oadp-1-4-release-notes.adoc

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,10 @@ The release notes for {oadp-first} describe new features and enhancements, depre
1414
For additional information about {oadp-short}, see link:https://access.redhat.com/articles/5456281[{oadp-first} FAQs]
1515
====
1616

17+
<<<<<<< HEAD
1718
include::modules/oadp-1-4-1-release-notes.adoc[leveloffset=+1]
19+
=======
20+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
1821
include::modules/oadp-1-4-0-release-notes.adoc[leveloffset=+1]
1922
include::modules/oadp-backing-up-dpa-configuration-1-4-0.adoc[leveloffset=+3]
2023
include::modules/oadp-upgrading-oadp-operator-1-4-0.adoc[leveloffset=+3]
@@ -28,4 +31,8 @@ include::modules/oadp-upgrading-oadp-operator-1-4-0.adoc[leveloffset=+3]
2831

2932
To upgrade from OADP 1.3 to 1.4, no Data Protection Application (DPA) changes are required.
3033

31-
include::modules/oadp-verifying-upgrade-1-4-0.adoc[leveloffset=+2]
34+
<<<<<<< HEAD
35+
include::modules/oadp-verifying-upgrade-1-4-0.adoc[leveloffset=+2]
36+
=======
37+
include::modules/oadp-verifying-upgrade-1-4-0.adoc[leveloffset=+2]
38+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)

edge_computing/image_based_upgrade/cnf-understanding-image-based-upgrade.adoc

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -76,8 +76,11 @@ include::modules/cnf-image-based-upgrade.adoc[leveloffset=+1]
7676
7777
* xref:../../edge_computing/image_based_upgrade/cnf-image-based-upgrade-base.adoc#cnf-image-based-upgrade[Performing an image-based upgrade for {sno} clusters with {lcao}]
7878
79+
<<<<<<< HEAD
7980
* xref:../../edge_computing/image_based_upgrade/ztp-image-based-upgrade.adoc#ztp-image-based-upgrade[Performing an image-based upgrade for {sno} clusters using {ztp}]
8081

82+
=======
83+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
8184
include::modules/cnf-image-based-upgrade-guidelines.adoc[leveloffset=+1]
8285
8386
[role="_additional-resources"]

edge_computing/image_based_upgrade/ztp-image-based-upgrade.adoc

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,17 +6,33 @@ include::_attributes/common-attributes.adoc[]
66

77
toc::[]
88

9+
<<<<<<< HEAD
910
// Lifecycle Agent (LCA)
1011

1112
You can use a single resource on the hub cluster, the `ImageBasedGroupUpgrade` custom resource (CR), to manage an imaged-based upgrade on a selected group of managed clusters through all stages.
1213
{cgu-operator-first} reconciles the `ImageBasedGroupUpgrade` CR and creates the underlying resources to complete the defined stage transitions, either in a manually controlled or a fully automated upgrade flow.
1314

1415
For more information about the image-based upgrade, see "Understanding the image-based upgrade for single-node OpenShift clusters".
16+
=======
17+
You can use a single resource on the hub cluster, the `ImageBasedGroupUpgrade` custom resource (CR), to manage an imaged-based upgrade on a selected group of managed clusters through all stages.
18+
{cgu-operator-first} reconciles the `ImageBasedGroupUpgrade` CR and creates the underlying resources to complete the defined stage transitions, either in a manually controlled or a fully automated upgrade flow.
19+
20+
// Lifecycle Agent (LCA)
21+
22+
include::modules/ztp-image-based-upgrade-concept.adoc[leveloffset=+1]
23+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
1524

1625
[role="_additional-resources"]
1726
.Additional resources
1827

28+
<<<<<<< HEAD
1929
* xref:../../edge_computing/image_based_upgrade/cnf-understanding-image-based-upgrade.adoc#cnf-understanding-image-based-upgrade[Understanding the image-based upgrade for single-node OpenShift clusters]
30+
=======
31+
* xref:../../backup_and_restore/control_plane_backup_and_restore/disaster_recovery/scenario-3-expired-certs.adoc#dr-scenario-3-recovering-expired-certs_dr-recovering-expired-certs[Recovering from expired control plane certificates]
32+
33+
////
34+
* xref:../../edge_computing/ztp-preparing-the-hub-cluster.adoc#ztp-preparing-the-ztp-git-repository-ver-ind_ztp-preparing-the-hub-cluster[Preparing the {ztp} site configuration repository for version independence]
35+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
2036
2137
include::modules/ztp-image-based-upgrade-concept.adoc[leveloffset=+1]
2238

@@ -34,6 +50,7 @@ include::modules/ztp-image-based-upgrade-procedure-steps.adoc[leveloffset=+1]
3450
* xref:../../backup_and_restore/application_backup_and_restore/backing_up_and_restoring/oadp-creating-backup-cr.adoc#oadp-creating-backup-cr-doc[Creating a Backup CR]
3551
3652
* xref:../../backup_and_restore/application_backup_and_restore/backing_up_and_restoring/restoring-applications.adoc#oadp-creating-restore-cr_restoring-applications[Creating a Restore CR]
53+
<<<<<<< HEAD
3754
3855
* xref:../../edge_computing/image_based_upgrade/ztp-image-based-upgrade.adoc#ztp-image-based-upgrade-supported-combinations_ztp-gitops[Supported action combinations]
3956
@@ -47,6 +64,9 @@ include::modules/ztp-image-based-upgrade-procedure-cancel.adoc[leveloffset=+1]
4764
* xref:../../edge_computing/image_based_upgrade/ztp-image-based-upgrade.adoc#ztp-image-based-upgrade-supported-combinations_ztp-gitops[Supported action combinations]
4865
4966
include::modules/ztp-image-based-upgrade-procedure-rollback.adoc[leveloffset=+1]
67+
=======
68+
////
69+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
5070

5171
[role="_additional-resources"]
5272
.Additional resources

hosted_control_planes/hcp-deploy/hcp-deploy-non-bm.adoc

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,11 @@ include::modules/hcp-non-bm-hc.adoc[leveloffset=+1]
5858
[role="_additional-resources"]
5959
.Additional resources
6060

61+
<<<<<<< HEAD
6162
* xref:../../hosted_control_planes/hcp-import.adoc#hcp-import-manual_hcp-import[Manually importing a hosted cluster]
63+
=======
64+
* xref:../../hosted_control_planes/hcp-import.adoc#hcp-import-manual_hcp-import[Manually importing a hosted control plane cluster]
65+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
6266
6367
include::modules/hcp-non-bm-hc-console.adoc[leveloffset=+2]
6468

installing/installing_openstack/installing-openstack-three-node.adoc

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,9 +8,18 @@ toc::[]
88

99
In {product-title} version {product-version}, you can install a three-node cluster on {rh-openstack-first}. A three-node cluster consists of three control plane machines, which also act as compute machines. This type of cluster provides a smaller, more resource efficient cluster, for cluster administrators and developers to use for testing, development, and production.
1010

11+
<<<<<<< HEAD
1112
You can install a three-node cluster on installer-provisioned infrastructure only.
13+
=======
14+
You can install a three-node cluster by using either installer-provisioned or user-provisioned infrastructure.
15+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)
1216

1317
include::modules/installation-three-node-cluster-cloud-provider.adoc[leveloffset=+1]
1418

1519
== Next steps
16-
* xref:../../installing/installing_openstack/installing-openstack-installer-custom.adoc#installing-openstack-installer-custom[Installing a cluster on OpenStack with customizations]
20+
<<<<<<< HEAD
21+
* xref:../../installing/installing_openstack/installing-openstack-installer-custom.adoc#installing-openstack-installer-custom[Installing a cluster on OpenStack with customizations]
22+
=======
23+
* xref:../../installing/installing_openstack/installing-openstack-installer-custom.adoc#installing-openstack-installer-custom[Installing a cluster on OpenStack with customizations]
24+
* xref:../../installing/installing_openstack/installing-openstack-user.adoc#installing-openstack-user[Installing a cluster on OpenStack on your own infrastructure]
25+
>>>>>>> c17ffd7cec (Adding the Security HCP cherrypick)

0 commit comments

Comments
 (0)