Skip to Main Content
Status Submitted
Workspace * IBM Cloud Ideas
Created by Guest
Created on Aug 20, 2026

Self-Service Identity Provider Configuration for ROKS HCP: Provide an ibmcloud oc CLI command (and Terraform resource parameter) to configure OpenID Connect identity providers on ROKS Hosted Control Plane clusters

ROKS clusters using the Hosted Control Plane (HyperShift) architecture manage authentication through the HostedCluster object on IBM's management plane. The OpenShift OAuth CR on the data plane is read-only — a ValidatingAdmissionPolicy blocks all modifications:The oauths "cluster" is invalid: ValidatingAdmissionPolicy 'config' with binding'config-binding' denied request: This resource cannot be created, updated, or deleted. Please ask your administrator to modify the resource in the HostedCluster object. This means customers cannot configure identity providers (OIDC, LDAP, SAML, etc.) on ROKS HCP clusters without opening a support case and waiting for IBM to manually modify the HostedCluster object.Without self-service identity provider configuration, every ROKS cluster deployment requires a support case for a routine configuration change. This adds days of delay to each cluster provisioning cycle and creates an operational dependency on IBM support for a standard day-2 operation.

Idea priority Urgent
Needed By Yesterday (Let's go already!)