Skip to content

feat!: volume-based TLS identities - #355

Draft
fcanovai wants to merge 6 commits into
mainfrom
dev/353
Draft

fcanovai wants to merge 6 commits into
mainfrom
dev/353

Conversation

@fcanovai

@fcanovai fcanovai commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Reworks how Klio references TLS material: whole-Secret mounts are replaced by file references that mount only what's needed, from any volume source.

BREAKING CHANGE: tlsSecretName, caSecretName, clientSecretName are removed

Replace whole-Secret TLS references with file references that mount only
what each consumer needs. Server and plugin identities become a
TLSIdentity: a single volume with the paths of the certificate and the
private key, so the pair always belongs together. CA bundles become file
references from a restricted set of volume sources (Secret, ConfigMap,
Projected, CSI), and the FileSource wrapper is dropped.

The Server API is `serverTlsIdentity` plus `clientCa`; the plugin uses
`clientTlsIdentity` plus `serverCa`. The paths are required, so the default
file names (tls.crt, tls.key, ca.crt) and their fallbacks are removed.

Pod-crossing paths verify through the CA bundles (Kopia
--server-cert-ca-file, gRPC RootCAs). Local Kopia server refresh calls
verify the served leaf by a fingerprint computed from the serving
certificate file on every call.

The CRDs, the deepcopy functions and the API reference are regenerated.
Existing Server and PluginConfiguration manifests must move to the new
fields.

Assisted-by: OpenCode
Assisted-By: Claude

Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
The WAL server rebuilds its TLS configuration (serving pair plus client CA
pool) on every handshake via GetConfigForClient, and the WAL client
re-reads its client identity per handshake via GetClientCertificate.
Rotated files take effect on new connections with zero downtime; rebuild
failures fail that handshake closed.

Assisted-by: OpenCode
Assisted-By: Claude

Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Document the `serverTlsIdentity`, `clientTlsIdentity`, `clientCa` and
`serverCa` fields and the volume sources they accept, in place of the
whole-Secret references. Update the sample manifests, including the
kustomize patches, to the new field names, and split the example PKI into
separate server and client CAs.

Assisted-by: OpenCode
Assisted-By: Claude

Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Add `credentialsFile` and `profile` to the Server `tier2.s3` configuration.
The file is an AWS shared credentials file mounted from a volume. The
operator exposes it to the server through AWS_SHARED_CREDENTIALS_FILE and
AWS_PROFILE. It cannot be combined with accessKeyId, secretAccessKey or
sessionToken, which keep working as before.

Kopia reads the file through the shared credentials provider of the Klio
Kopia build. The server's own S3 client uses a provider that re-reads the
file, so rotated credentials are picked up without a restart.

Assisted-By: Claude

Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Add a section on supplying S3 credentials from an AWS shared credentials
file mounted from a volume, with the `credentialsFile` and `profile` fields.
It explains that the file cannot be combined with `accessKeyId`,
`secretAccessKey` or `sessionToken`, and that Kopia and the Klio server
re-read it, so rotated credentials need no restart.

Assisted-By: Claude

Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>
Temporary change: build Kopia from the cert-reload branch of
github.com/fcanovai/kopia instead of the klio branch of
cloudnative-pg/kopia. That branch makes the Kopia server reload its TLS
certificates and CA bundles without a restart, and reads the AWS shared
credentials file used by the S3 credentials file support.

Revert to the upstream klio branch once the Kopia changes land there.

Assisted-By: Claude

Signed-off-by: Francesco Canovai <francesco.canovai@enterprisedb.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant