ROKS clusters using the Hosted Control Plane (HyperShift) architecture manage authentication through the HostedCluster object on IBM's management plane. The OpenShift OAuth CR on the data plane is read-only — a ValidatingAdmissionPolicy blocks all modifications:The oauths "cluster" is invalid: ValidatingAdmissionPolicy 'config' with binding'config-binding' denied request: This resource cannot be created, updated, or deleted. Please ask your administrator to modify the resource in the HostedCluster object. This means customers cannot configure identity providers (OIDC, LDAP, SAML, etc.) on ROKS HCP clusters without opening a support case and waiting for IBM to manually modify the HostedCluster object.Without self-service identity provider configuration, every ROKS cluster deployment requires a support case for a routine configuration change. This adds days of delay to each cluster provisioning cycle and creates an operational dependency on IBM support for a standard day-2 operation.
| Idea priority | Urgent |
| Needed By | Yesterday (Let's go already!) |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.