Add missing Pod IPs to created certificates
@Techassi ci sta già lavorando.
Dal 25/2/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Some tools call the Pods via their PodIP, e.g. Prometheus when using a ServiceMonitor.
For this to work with HTTPS-enabled products, we need to add the Pod IP to the certificate because
- The clients should be able to validate the cert
- Some products (currently only NiFi) raise an "Invalid SNI" error if they can not find a matching cert in it's keystore
There is currently already code for this.
The Pod IPs are gathered here:
https://github.com/stackabletech/secret-operator/blob/e5224ab480e219e434ddc695c9361a16a56a43ed/rust/operator-binary/src/backend/pod_info.rs#L142-L153
and stuffed into the certificate here
https://github.com/stackabletech/secret-operator/blob/e5224ab480e219e434ddc695c9361a16a56a43ed/rust/operator-binary/src/backend/mod.rs#L229
However the comment already highlights the problem:
This will generally be empty, since Kubernetes assigns pod IPs after CSI plugins are successful
Because of this, we are lacking SAN entries for the Pod IPs.
I don't know if this "is even possible" with our current architecture of secret-operator being a CSI driver.
So I though "maybe listener-op can help"? Not from the top of my head, as it itself is "only" a CSI driver, so the Pod has no IPs assigned when it is running as well. listener-op can currently only block Pod creation until a Service (such as a LoadBalancer) has an address assigned. But there might be some other clever way how listener-op can do this which I didn't though of.
Another though is that certificate hot-reloading should work, because we can add the IP to the cert after the Pod has an IP assigned.
But that's a bigger story - e.g. do all tools support this?
Run secret-op as init container? As sidecar?
- Lingua principale
- Rust
- Stelle
- 13
- Fork
- 8
- Merge medio
- 1g 8h
- PR unite (30g)
- 10
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di stackabletech/secret-operator
-
type/bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
stackabletech/secret-operator#754 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 48/100
stackabletech/secret-operator#753 · 1 commento ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
stackabletech/secret-operator#720 · 1 commento ·
-
customer-request type/bug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 38/100
stackabletech/secret-operator#666 · 2 commenti ·
-
customer-request type/feature-improvement
stackabletech/secret-operator#630 · 7 commenti · 1 assegnatario ·
Tutte le issue di stackabletech/secret-operator
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
web-infra-dev/rspack#15847 ·