Enable usage of dynamic leaf certificates using a certificate resolver
@Techassi đang làm issue này rồi.
Từ ngày 5/3/2024.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Currently to use TLS with webhooks, you have to manually mount a volume with the CA.
This PR: https://github.com/stackabletech/operator-rs/pull/736 adds a module to the framework that supports creating CAs and leaf certificates. Here we could just call the code to generate the certs and call the server, but then there is no way for them to be swapped out if they expire.
This ticket is about writing code to - instead of mounting a single cert - resolve a cert dynamically, allowing us to swap out expired certs while the Webhook server is running.
This resolver will be used by the stackable-webhook crate.
Follow up of #736.
Acceptance criteria
- This TODO is resolved, and the AutoGenerate feature on the CA for the webhook works
- Ngôn ngữ chính
- Rust
- Star
- 167
- Fork
- 19
- Merge trung bình
- 1 ngày 6 giờ
- Pull request đã merge (30 ngày)
- 9
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của stackabletech/operator-rs
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
stackabletech/operator-rs#1273 · 1 bình luận ·
-
Improve label mechanisms Đang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
stackabletech/operator-rs#1077 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
stackabletech/operator-rs#1063 ·
-
stackable-versioned: Require inner module definitions to have the same visibility as the parent Đang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
stackabletech/operator-rs#1028 ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
stackabletech/operator-rs#965 ·
Tất cả issue của stackabletech/operator-rs
Issue tương tự
-
Replayed reasoning items send "content": null, which the Responses API schema does not permit Đang mởbug CLI custom-model
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
rust-bitcoin/rust-bitcoin#6930 · 1 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
fulcrumgenomics/ferro-hgvs#2251 ·
-
Missing examples for `Allocator` Đang mởA-allocators A-docs C-enhancement T-libs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100