Skip to main content

🔄 openshift-update-proxy

CI Release PyPI License

A small Flask based service which forwards HTTP requests to api.openshift.com and mirror.openshift.com. Built for restricted networks where OpenShift clusters have no direct internet access, but a central egress proxy (or a single host with internet access) exists.

Features

  • 🔀 Update Graph Proxy - forwards Cincinnati update graph requests (/api/upgrades_info/v1/graph) to api.openshift.com
  • 📦 Mirror Proxy - forwards requests for clients and release artifacts to mirror.openshift.com/pub
  • 🔏 Signature Store - serves release image signatures for ClusterVersion.spec.signatureStores (OpenShift 4.14+)
  • 🗺️ ConfigMap Generator - renders ready-to-apply signature ConfigMaps for the classic disconnected verification workflow
  • 🚦 Egress Proxy Aware - honors HTTPS_PROXY / NO_PROXY for all upstream requests
  • 🐳 Hardened Container - UBI9 based, rootless (UID 1001), digest-pinned base image, Cosign signed
  • Helm Chart - deploy to Kubernetes/OpenShift with probes and sane security defaults
  • 🩺 Health Endpoint - /healthz for liveness and readiness probes

How it works

flowchart LR
    subgraph restricted["Restricted network"]
        CVO["Cluster Version Operator"]
        ADMIN["Admin (oc / curl)"]
        PROXY["openshift-update-proxy"]
    end

    subgraph internet["Internet"]
        API["api.openshift.com"]
        MIRROR["mirror.openshift.com"]
    end

    CVO -- "/api/upgrades_info/v1/graph" --> PROXY
    CVO -- "/signatures/sha256=…" --> PROXY
    ADMIN -- "/configmaps/sha256=…" --> PROXY
    ADMIN -- "/pub/…" --> PROXY

    PROXY -- "optional egress proxy (HTTPS_PROXY)" --> EGRESS["Egress Proxy"]
    EGRESS --> API
    EGRESS --> MIRROR

Endpoints

Endpoint Upstream Purpose
/api/<path> https://api.openshift.com/api/ Cincinnati update graph (/api/upgrades_info/v1/graph)
/pub/<path> https://mirror.openshift.com/pub/ OpenShift mirror (clients, release artifacts)
/signatures/<path> https://mirror.openshift.com/pub/openshift-v4/signatures/openshift/release/ Release image signature store
/configmaps/sha256=<digest> derived from signature store Ready-to-apply signature ConfigMap (YAML)
/healthz - Health check for liveness/readiness probes

Configuration

All configuration is done via environment variables:

Variable Default Description
HTTPS_PROXY - Egress proxy for upstream requests (standard requests behaviour, NO_PROXY is honored)
INSECURE_SKIP_TLS_VERIFY false Skip TLS certificate verification for upstream requests (true/1/yes)
API_UPSTREAM https://api.openshift.com/api/ Cincinnati API base URL
MIRROR_UPSTREAM https://mirror.openshift.com/pub/ Mirror base URL
SIGNATURE_UPSTREAM https://mirror.openshift.com/pub/openshift-v4/signatures/openshift/release/ Signature store base URL
REQUEST_TIMEOUT 30 Upstream request timeout in seconds
LISTEN_HOST 0.0.0.0 Listen address
LISTEN_PORT 5000 Listen port

Quick Start

Container

docker run --rm -p 5000:5000 \
  -e HTTPS_PROXY=http://proxy.example.com:3128 \
  ghcr.io/slauger/openshift-update-proxy:latest

The image is based on registry.access.redhat.com/ubi9/python-314, runs as UID 1001 and is built from the Containerfile in this repository.

Helm

The chart is published as an OCI artifact to ghcr.io on every release:

helm install update-proxy oci://ghcr.io/slauger/charts/openshift-update-proxy \
  --set env[0].name=HTTPS_PROXY,env[0].value=http://proxy.example.com:3128

Or from a git checkout: helm install update-proxy ./chart

PyPI

python3 -m venv .venv && source .venv/bin/activate
pip install openshift-update-proxy
openshift-update-proxy

Cluster integration

Update graph

Point the ClusterVersion upstream at the proxy:

apiVersion: config.openshift.io/v1
kind: ClusterVersion
metadata:
  name: version
spec:
  upstream: http://update-proxy.example.com:5000/api/upgrades_info/v1/graph

Release signatures

For updates by digest (oc adm upgrade --to-image ...@sha256:...) the CVO must verify the release image signature. There are two ways to get signatures into a restricted cluster:

Option 1: Signature store (OpenShift 4.14+)

Point the cluster at the /signatures/ endpoint of the proxy:

apiVersion: config.openshift.io/v1
kind: ClusterVersion
metadata:
  name: version
spec:
  signatureStores:
    - url: http://update-proxy.example.com:5000/signatures

Option 2: Signature ConfigMap

The /configmaps/ endpoint fetches all signatures for a release digest and renders a ready-to-apply ConfigMap (same format as oc adm release mirror / oc-mirror produces):

DIGEST=$(oc adm release info quay.io/openshift-release-dev/ocp-release:4.16.8-x86_64 -o jsonpath='{.digest}')
curl -s "http://update-proxy.example.com:5000/configmaps/${DIGEST/:/=}" | oc apply -f -

The ConfigMap is created in openshift-config-managed with the release.openshift.io/verification-signatures label, where the CVO picks it up.

Local Development

python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
openshift-update-proxy

Run tests and linting:

make test
make lint

Build the container image:

make build

Supply Chain Security

  • The UBI9 base image is pinned by digest and kept up to date by Renovate; remaining CVEs are patched at build time via dnf upgrade.
  • Python and GitHub Actions dependencies are also managed by Renovate (with automerge for non-major updates).
  • Releases are fully automated with python-semantic-release based on Conventional Commits and published to PyPI.
  • Container images are signed with Cosign (keyless, GitHub Actions OIDC). Verify with:
cosign verify \
  --certificate-identity-regexp 'https://github.com/slauger/openshift-update-proxy/.*' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  ghcr.io/slauger/openshift-update-proxy:latest

License

Apache License 2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

openshift_update_proxy-1.0.1.tar.gz (14.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

openshift_update_proxy-1.0.1-py3-none-any.whl (11.8 kB view details)

Uploaded Python 3

File details

Details for the file openshift_update_proxy-1.0.1.tar.gz.

File metadata

  • Download URL: openshift_update_proxy-1.0.1.tar.gz
  • Upload date:
  • Size: 14.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for openshift_update_proxy-1.0.1.tar.gz
Algorithm Hash digest
SHA256 29304abc5944873ef598393c16f15d4d1c26f510e47279f7209aa3079f2e6227
MD5 f8f542238dda6457fe5e047f5f4b8d45
BLAKE2b-256 075020cc7df4c4c9de9624b5c35ff22f1e6986f9ed781c9c2f29c940a2de9182

See more details on using hashes here.

Provenance

The following attestation bundles were made for openshift_update_proxy-1.0.1.tar.gz:

Publisher: release.yml on slauger/openshift-update-proxy

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file openshift_update_proxy-1.0.1-py3-none-any.whl.

File metadata

File hashes

Hashes for openshift_update_proxy-1.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 a0b8a67788b2212c811265f97140e7ace6c619edcb9dd96ba16c0f9db95efe08
MD5 55b857728c5d2ae30ecb1a4770eccdbf
BLAKE2b-256 325f2e8b023a445974cbd144c16f5797b39a9b3882a0c5b3b62007bc48cfda42

See more details on using hashes here.

Provenance

The following attestation bundles were made for openshift_update_proxy-1.0.1-py3-none-any.whl:

Publisher: release.yml on slauger/openshift-update-proxy

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 files

1.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page