-
Notifications
You must be signed in to change notification settings - Fork 65
[Bug][VIC] Able to Add one VCH to multiple projects in Admiral #264
Comments
Which scenario are you referring to? |
If it's not supported to add the same VCH to multiple projects, my concern is that there is no way of knowing in the UI which projects a VCH is assigned to already... |
Also, per vmware/vic-product#1651 (comment), the whitelisting might be problematic if you share a VCH between projects. So, do we want to recommend against sharing VCHs between projects, even if it is supported? |
@martin-borisov ^^^^ |
After looking into how enabling content trust on a project modifies the VCHs that are associated with that project (see #1688), I have doubts about whether adding the same VCH to multiple projects should be supported. It seems to me from the VCH content trust test description that if you add a VCH to a project and enable content trust on that project, the VCH is automatically put into whitelist mode and the VCH can only pull images from that registry, regardless of the settings with which the VCH was deployed. @martin-borisov, what happens if you add the same VCH to two projects, one that has content trust enabled and one that doesn't? |
@martin-borisov I did a few tests in vmware/vic-product#1688 (comment) by adding a VCH to two projects, with and without CT enabled, and it seems that the CT settings are only applied to the VCH by the first project to which you add the VCH. Any CT settings that you make in the second project are ignored by the VCH, even if CT is disabled on the first project. So, does this make us want to reappraise the statement that you can add the same VCH to multiple projects? I think that the project-level registry lists also cause problems if a VCH is in more than one project. |
@martin-borisov @stuclem @lazarin It's not actually the first project added - it's the first project the VCH discovers that claims ownership of it. Discovery is prompted by There are two other behaviours we should confirm:
The third case would occur if the whitelist provided when the VCH was deployed is not a superset of the CT whitelist. |
@hickeng when I tested this, only the harbor instance running in the appliance was added to the whitelist. If the project includes other registries that are external to the appliance, they are not added to the whitelist. |
@hickeng I just did another test, for bullets 1 & 2, just to make sure that only the default reg is being added to the VCH whitelist:
So, according to your comment above, the behaviour is as it should be, correct? |
@hickeng, regarding your comment "It's not actually the first project added - it's the first project the VCH discovers that claims ownership of it. Discovery is prompted by |
I am able to add One VCH to multiple projects in 1.3.1. This scenario is not supported and users should not be allowed to do this.
Screenshots attached below:
Let me know if any additional details are required. Thanks
The text was updated successfully, but these errors were encountered: