Feature: External Database TLS Certificate configuration
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- helm, kubernetes
- 领域
- cloud, devops, infrastructure
调研方向
首先检查配置外部数据库连接的 chart 模板和 values 文件。确定现有数据库设置如何传递到 deployment 中,然后定义 TLS 证书参数并更新 chart 文档。完成标准是集成可选的 CA、客户端证书和密钥设置,同时不影响不使用 TLS 的 deployment。
由索引模型根据 Issue 内容生成。
描述
Description of the change
This feature request adds support for configuring TLS certificates when connecting to an external database via the NextCloud Helm chart. The proposed change introduces new Helm chart parameters that allow users to specify certificate details such as the TLS CA certificate, client certificate, and corresponding key. With these additions, users can enable secure, encrypted connections to external databases by simply providing the necessary certificate paths or inline values in the chart's configuration. This update involves modifying the chart templates and values files to integrate these new settings seamlessly into the existing deployment process.
Benefits
- Enhanced Security: Encrypts communication between NextCloud and the external database, reducing the risk of data interception.
- Compliance: Helps meet organizational security policies and regulatory requirements that mandate encrypted connections.
- Flexibility: Allows users to integrate with existing certificate management systems, improving compatibility with managed external database services.
Possible drawbacks
- Increased Complexity: Adds additional configuration options which might complicate the setup for users who are less familiar with TLS and certificate management.
- Potential for Misconfiguration: Incorrectly specified certificate paths or values could lead to connection failures, necessitating thorough documentation and testing.
- Upgrade Considerations: Existing deployments without TLS settings may require careful review during upgrades to ensure a smooth transition.
Additional information
- Documentation updates will be provided to guide users through configuring TLS certificates within the Helm chart.
- This feature is optional and will not impact users who do not need to configure TLS for their external databases.
- 主要语言
- Go Template
- 星标
- 536
- 派生
- 316
- 平均合并
- 4 天 16 小时
- 30 天内合并 PR
- 2
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
nextcloud/helm 的其他 Issue
-
No native support for REDIS_USER enviroment var可能已有人在做 @jholmes802 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set可能已有人在做 @JanWelker 于 17 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 78/100
-
External Redis not working: redis-session.ini: Permission denied可能已有人在做 @antoinetran 于 22 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 55/100
相似的 Issue
-
gcsartifact: deleting a missing version returns an error可能已有人在做 @ktsoator 今天认领。 未关闭bug
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 2 天内回复
-
api: run samples
难度 2/5 1-3 小时 新手友好度 62/100
GoogleCloudPlatform/python-docs-samples#14633 ·
维护者通常 5 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
apache/iceberg-python#4093 ·
维护者通常 1 天内回复
-
enhancement exporter/awss3 needs triage
难度 2/5 1-3 小时 新手友好度 66/100
open-telemetry/opentelemetry-collector-contrib#51905 · 1 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 66/100
Azure/osdu-spi-stack#324 ·
维护者通常 1 天内回复