Repository navigation
Conversation
Replace whole-Secret TLS references with file references that mount only what each consumer needs. Server and plugin identities become a TLSIdentity: a single volume with the paths of the certificate and the private key, so the pair always belongs together. CA bundles become file references from a restricted set of volume sources (Secret, ConfigMap, Projected, CSI), and the FileSource wrapper is dropped. The Server API is `serverTlsIdentity` plus `clientCa`; the plugin uses `clientTlsIdentity` plus `serverCa`. The paths are required, so the default file names (tls.crt, tls.key, ca.crt) and their fallbacks are removed. Pod-crossing paths verify through the CA bundles (Kopia --server-cert-ca-file, gRPC RootCAs). Local Kopia server refresh calls verify the served leaf by a fingerprint computed from the serving certificate file on every call. The CRDs, the deepcopy functions and the API reference are regenerated. Existing Server and PluginConfiguration manifests must move to the new fields. Assisted-by: OpenCode Assisted-By: Claude Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
The WAL server rebuilds its TLS configuration (serving pair plus client CA pool) on every handshake via GetConfigForClient, and the WAL client re-reads its client identity per handshake via GetClientCertificate. Rotated files take effect on new connections with zero downtime; rebuild failures fail that handshake closed. Assisted-by: OpenCode Assisted-By: Claude Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Document the `serverTlsIdentity`, `clientTlsIdentity`, `clientCa` and `serverCa` fields and the volume sources they accept, in place of the whole-Secret references. Update the sample manifests, including the kustomize patches, to the new field names, and split the example PKI into separate server and client CAs. Assisted-by: OpenCode Assisted-By: Claude Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Add `credentialsFile` and `profile` to the Server `tier2.s3` configuration. The file is an AWS shared credentials file mounted from a volume. The operator exposes it to the server through AWS_SHARED_CREDENTIALS_FILE and AWS_PROFILE. It cannot be combined with accessKeyId, secretAccessKey or sessionToken, which keep working as before. Kopia reads the file through the shared credentials provider of the Klio Kopia build. The server's own S3 client uses a provider that re-reads the file, so rotated credentials are picked up without a restart. Assisted-By: Claude Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Add a section on supplying S3 credentials from an AWS shared credentials file mounted from a volume, with the `credentialsFile` and `profile` fields. It explains that the file cannot be combined with `accessKeyId`, `secretAccessKey` or `sessionToken`, and that Kopia and the Klio server re-read it, so rotated credentials need no restart. Assisted-By: Claude Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Temporary change: build Kopia from the cert-reload branch of github.com/fcanovai/kopia instead of the klio branch of cloudnative-pg/kopia. That branch makes the Kopia server reload its TLS certificates and CA bundles without a restart, and reads the AWS shared credentials file used by the S3 credentials file support. Revert to the upstream klio branch once the Kopia changes land there. Assisted-By: Claude Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reworks how Klio references TLS material: whole-Secret mounts are replaced by file references that mount only what's needed, from any volume source.
BREAKING CHANGE: tlsSecretName, caSecretName, clientSecretName are removed