Bring-your-own serving certificate for the aggregated API server
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- go, kubernetes
- Ambito
- api, backend, documentation, infrastructure, security, testing
Direzione di ricerca
Locate the aggregated API server's Secret handling and certificate reload entry points first, then review the existing unit-test and Kind setup. Verify the supplied Secret is never written, rotation works without a restart, expiry failures are clear, and the documentation explains cert-manager CA injection and the manage-ca-bundle annotation.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Since #140 and #141, the aggregated API server generates its serving CA in the coder-k8s-apiserver-tls Secret and keeps the APIService caBundle in sync. Some clusters want to supply their own certificate instead, for example issued by cert-manager or a corporate CA.
Today the server adopts any valid Secret unchanged, but it still renews the serving certificate with the Secret's CA key, so it needs that key. The opt-out annotation coder.com/manage-ca-bundle=false only stops the caBundle sync.
Proposal: a bring-your-own mode (a flag, or a Secret annotation) in which the server:
- only reads a
kubernetes.io/tlsSecret, possibly without the CA key; - never generates or renews certificates;
- reloads the certificate when the Secret changes;
- fails clearly when the certificate is close to expiry.
Document how this mode works with cert-manager's CA injector and with the opt-out annotation.
Acceptance:
- With BYO mode on, the server serves the supplied certificate and never writes the Secret. Show this with unit tests and a Kind proof.
- Rotating the supplied Secret is picked up without a restart.
- The docs cover setup with cert-manager.
Owner: maintainer desk. Trigger: user demand, or after the namespaced Role issue lands. Refs #137.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: medium
- Lingua principale
- Go
- Stelle
- 4
- Fork
- 3
- Merge medio
- 3h 15m
- PR unite (30g)
- 31
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di coder/coder-k8s
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
coder/coder-k8s#117 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di coder/coder-k8s
Issue simili
-
priority: low 🌱 type: enhancement 💅🏼
Difficoltà 2/5 Mezza giornata Idoneità per principianti 84/100
nebari-dev/llm-serving-pack#199 ·
I maintainer di solito rispondono entro 3 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
area/helm kind/bug priority/backlog triage/accepted
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
lexfrei/cloudflare-tunnel-gateway-controller#889 ·
I maintainer di solito rispondono entro 1 giorno
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
wavefnd/wave-platform#140 ·
-
compiler/runtime
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
golang/go#81797 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno