Bring-your-own serving certificate for the aggregated API server
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 52/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- go, kubernetes
- 領域
- api, backend, documentation, infrastructure, security, testing
調査の方向性
Locate the aggregated API server's Secret handling and certificate reload entry points first, then review the existing unit-test and Kind setup. Verify the supplied Secret is never written, rotation works without a restart, expiry failures are clear, and the documentation explains cert-manager CA injection and the manage-ca-bundle annotation.
索引モデルが issue の本文から書いたものです。
説明
Since #140 and #141, the aggregated API server generates its serving CA in the coder-k8s-apiserver-tls Secret and keeps the APIService caBundle in sync. Some clusters want to supply their own certificate instead, for example issued by cert-manager or a corporate CA.
Today the server adopts any valid Secret unchanged, but it still renews the serving certificate with the Secret's CA key, so it needs that key. The opt-out annotation coder.com/manage-ca-bundle=false only stops the caBundle sync.
Proposal: a bring-your-own mode (a flag, or a Secret annotation) in which the server:
- only reads a
kubernetes.io/tlsSecret, possibly without the CA key; - never generates or renews certificates;
- reloads the certificate when the Secret changes;
- fails clearly when the certificate is close to expiry.
Document how this mode works with cert-manager's CA injector and with the opt-out annotation.
Acceptance:
- With BYO mode on, the server serves the supplied certificate and never writes the Secret. Show this with unit tests and a Kind proof.
- Rotating the supplied Secret is picked up without a restart.
- The docs cover setup with cert-manager.
Owner: maintainer desk. Trigger: user demand, or after the namespaced Role issue lands. Refs #137.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: medium
- 主要言語
- Go
- スター
- 4
- フォーク
- 3
- 平均マージ
- 3時間 15分
- マージ済み PR(30日)
- 31
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
coder/coder-k8s のほかの issue
coder/coder-k8s の issue をすべて見る
似ている issue
-
Remove CAAPFオープンkind/chore kind/cleanup needs-area
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
rancher/turtles#2848 · コメント 3 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
priority: low 🌱 type: enhancement 💅🏼
難易度 2/5 半日 初心者へのやさしさ 84/100
nebari-dev/llm-serving-pack#199 ·
メンテナーはふだん 3 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
kedacore/keda#8225 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信