Bring-your-own serving certificate for the aggregated API server
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 52/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- go, kubernetes
- 领域
- api, backend, documentation, infrastructure, security, testing
调研方向
Locate the aggregated API server's Secret handling and certificate reload entry points first, then review the existing unit-test and Kind setup. Verify the supplied Secret is never written, rotation works without a restart, expiry failures are clear, and the documentation explains cert-manager CA injection and the manage-ca-bundle annotation.
由索引模型根据 Issue 内容生成。
描述
Since #140 and #141, the aggregated API server generates its serving CA in the coder-k8s-apiserver-tls Secret and keeps the APIService caBundle in sync. Some clusters want to supply their own certificate instead, for example issued by cert-manager or a corporate CA.
Today the server adopts any valid Secret unchanged, but it still renews the serving certificate with the Secret's CA key, so it needs that key. The opt-out annotation coder.com/manage-ca-bundle=false only stops the caBundle sync.
Proposal: a bring-your-own mode (a flag, or a Secret annotation) in which the server:
- only reads a
kubernetes.io/tlsSecret, possibly without the CA key; - never generates or renews certificates;
- reloads the certificate when the Secret changes;
- fails clearly when the certificate is close to expiry.
Document how this mode works with cert-manager's CA injector and with the opt-out annotation.
Acceptance:
- With BYO mode on, the server serves the supplied certificate and never writes the Secret. Show this with unit tests and a Kind proof.
- Rotating the supplied Secret is picked up without a restart.
- The docs cover setup with cert-manager.
Owner: maintainer desk. Trigger: user demand, or after the namespaced Role issue lands. Refs #137.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: medium
- 主要语言
- Go
- 星标
- 4
- 派生
- 3
- 平均合并
- 3 小时 15 分钟
- 30 天内合并 PR
- 31
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
coder/coder-k8s 的其他 Issue
相似的 Issue
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
priority/4/normal status/needs-triage type/bug/unconfirmed
难度 2/5 1-3 小时 新手友好度 78/100
authelia/authelia#13292 · 1 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 68/100
blinklabs-io/actions#138 ·
维护者通常 1 天内回复
-
[UI] AlbumDetails collapses multi-genre list to single primary genre on viewports < lg breakpoint未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复