diff --git a/Chart.yaml b/Chart.yaml index 78f3585..bc67cf2 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -1,4 +1,4 @@ apiVersion: v1 name: pgdog -version: v0.83 -appVersion: "v0.1.58" +version: v0.84 +appVersion: "v0.1.60" diff --git a/templates/config.yaml b/templates/config.yaml index 67af5bf..838f5e1 100644 --- a/templates/config.yaml +++ b/templates/config.yaml @@ -87,6 +87,9 @@ data: tls_private_key = {{ .Values.tlsPrivateKey | quote }} {{- end }} {{- end }} + {{- if .Values.tlsClientCaCertificate }} + tls_client_ca_certificate = {{ .Values.tlsClientCaCertificate | quote }} + {{- end }} {{- if hasKey .Values "tlsClientRequired" }} tls_client_required = {{ .Values.tlsClientRequired }} {{- end }} @@ -98,6 +101,12 @@ data: {{- else if .Values.tlsServerCaCertificate }} tls_server_ca_certificate = {{ .Values.tlsServerCaCertificate | quote }} {{- end}} + {{- if .Values.tlsServerCertificate }} + tls_server_certificate = {{ .Values.tlsServerCertificate | quote }} + {{- end }} + {{- if .Values.tlsServerPrivateKey }} + tls_server_private_key = {{ .Values.tlsServerPrivateKey | quote }} + {{- end }} {{- if hasKey .Values "shutdownTimeout" }} shutdown_timeout = {{ include "pgdog.intval" .Values.shutdownTimeout }} {{- end }} @@ -349,6 +358,12 @@ data: {{- if hasKey . "lbWeight" }} lb_weight = {{ include "pgdog.intval" .lbWeight }} {{- end }} + {{- if .tlsServerCertificate }} + tls_server_certificate = {{ .tlsServerCertificate | quote }} + {{- end }} + {{- if .tlsServerPrivateKey }} + tls_server_private_key = {{ .tlsServerPrivateKey | quote }} + {{- end }} {{- end }} {{- range .Values.mirrors }} diff --git a/templates/secrets.yaml b/templates/secrets.yaml index 9000d3f..d71a6b6 100644 --- a/templates/secrets.yaml +++ b/templates/secrets.yaml @@ -3,6 +3,9 @@ [[users]] name = {{ .name | quote }} database = {{ .database | quote }} +{{- if .identity }} +identity = {{ .identity | quote }} +{{- end }} {{- if .passwords }} passwords = [{{ range $i, $p := .passwords }}{{ if $i }}, {{ end }}{{ $p | quote }}{{ end }}] {{- else if .password }} diff --git a/test/values-tls-paths.yaml b/test/values-tls-paths.yaml index f9a65f1..d923115 100644 --- a/test/values-tls-paths.yaml +++ b/test/values-tls-paths.yaml @@ -1,9 +1,19 @@ # Test explicit TLS path settings in pgdog.toml. tlsCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem tlsPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key +tlsClientCaCertificate: /etc/ssl/certs/ca-certificates.crt tlsServerCaCertificate: /etc/ssl/certs/ca-certificates.crt +tlsServerCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem +tlsServerPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key + +users: + - name: app + database: primary + identity: app databases: - name: primary host: postgres.example.com port: 5432 + tlsServerCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem + tlsServerPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key diff --git a/values.yaml b/values.yaml index be912f3..c9bee14 100644 --- a/values.yaml +++ b/values.yaml @@ -241,11 +241,14 @@ loadBalancingStrategy: round_robin # databases contains the list of database entries in pgdog.toml # Supports all arguments from pgdog.toml. Arguments are named in # camelCase format. +# Set tlsServerCertificate and tlsServerPrivateKey on a database to use +# a different certificate and key for its PostgreSQL connections. databases: [] # users contains the list of user entries in users.toml # Supports all arguments from users.toml. Arguments are named in # camelCase format. +# Set identity on a user to match the identity in its client TLS certificate. users: [] # mirrors contains a list of databases to replicate traffic from/to. @@ -619,6 +622,16 @@ control: # Note: certificates are regenerated on every helm upgrade. # tlsGenerateSelfSignedCert: false +# tlsClientCaCertificate is the path to the CA certificate used to verify +# client TLS certificates. Mount it with extraVolumes/extraVolumeMounts. +# tlsClientCaCertificate: /etc/pgdog-client-ca/ca.crt + +# tlsServerCertificate and tlsServerPrivateKey are paths to the certificate +# and private key PgDog presents when authenticating to PostgreSQL with mTLS. +# Mount these files with extraVolumes/extraVolumeMounts. +# tlsServerCertificate: /etc/pgdog-server-tls/tls.crt +# tlsServerPrivateKey: /etc/pgdog-server-tls/tls.key + # rdsCertificateBundle includes the AWS RDS CA certificate bundle so pgdog can # verify TLS connections to RDS/Aurora instances. When enabled, # tls_server_ca_certificate is automatically configured in pgdog.toml.