Commit Graph
3 Commits
Author SHA1 Message Date
c0ff8684ce feat(common): Add support for secretRefs when defining custom CA for use with S3 credentials (#40385)
**Description**

This PR builds up on #40000 by adding an additional key -
`credentials.$name.customCASecretRef`. This allows referencing secrets
via the already familiar `configMapRef`/`secretRef` pattern, using the
`name` and `expandObjectName` keys to reference secrets defined under
`.Values.secret`. Additionally, it also adds a
`credentials.$name.customCASecretRef.key` forcing users to specify the
key in the secret which contains the CA, for maximum flexibility.

⚒️ Fixes  # <!--(issue)-->

**⚙️ Type of change**

- [X] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] 🔃 Refactor of current code
- [X] 📜 Documentation Changes

**🧪 How Has This Been Tested?**
<!--
Please describe the tests that you ran to verify your changes. Provide
instructions so we can reproduce. Please also list any relevant details
for your test configuration
-->

I tested rendering the same CA secret using both the current `customCA`
implementation and the new `.secret.$name` + `customCASecretRef` way.
Also added unit tests for CI.

**📃 Notes:**

Regarding CNPG support - the changes in this PR and from #40000 should
also work for CNPG. As far as i can tell it requires the CA secret to be
referenced under a key called `endpointCA` in the following way
([docs](https://cloudnative-pg.io/documentation/1.16/api_reference/#backupstatus),
[CRD
def](https://github.com/cloudnative-pg/cloudnative-pg/blob/6ae2fb61bee4f959545bceeacfc5a209b2358668/config/crd/bases/postgresql.cnpg.io_backups.yaml#L256)):

```yaml
...
barmanObjectStore:
  endpointURL: ...
  ...
  endpointCA:
    name: secret-name
    key: secret-key
```

Note that while the current [in-tree barman cloud support is being
deprecated in favour of a barman cloud
plugin](https://cloudnative-pg.io/releases/cloudnative-pg-1-26.0-released/#barman-cloud-deprecation-begins),
the [migration
guide](https://cloudnative-pg.io/plugin-barman-cloud/docs/migration/)
says the new `ObjectStore` CRD has a **direct mapping** between it and
the legacy `barmanObjectStore`. Therefore, the example above can be
translated to:

```yaml
apiVersion: barmancloud.cnpg.io/v1
kind: ObjectStore
...
spec:
  configuration:
    endpointURL: ...
    ...
    endpointCA:
      name: secret-name
      key: secret-key
```

**✔️ Checklist:**

- [X] ⚖️ My code follows the style guidelines of this project
- [X] 👀 I have performed a self-review of my own code
- [X] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [X] 📄 I have made changes to the documentation
- [X] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [X] ⬆️ I increased versions for any altered app according to semantic
versioning
- [X] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or
`fix(docs):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._

---------

Signed-off-by: Kjeld Schouten <info@kjeldschouten.nl>
Co-authored-by: Kjeld Schouten <info@kjeldschouten.nl>
2025-10-06 12:04:39 +02:00
astro-stanandGitHub 9ff148b37a feat(common): Improve traefik service integration (#40293)
**Description**

This PR improves the traefik service integration by:

- Adds ability to generate
[ServersTransport](https://doc.traefik.io/traefik/reference/routing-configuration/kubernetes/crd/http/serverstransport/)
resources
- Adds docs regarding the traefik service integration to the website

⚒️ Fixes  # NA

**⚙️ Type of change**

- [X] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] 🔃 Refactor of current code
- [X] 📜 Documentation Changes

**🧪 How Has This Been Tested?**

What I have tested:

- ServersTransport generation
- `traefik.ingress.kubernetes.io/service.serversscheme` and
`traefik.ingress.kubernetes.io/service.serverstransport` service
annotations generation
- Traefik:
- talks over HTTPS when
`traefik.ingress.kubernetes.io/service.serversscheme: "https"` is set on
the service
   - skips TLS verification when `insecureSkipVerify: true`
- Successfully verifies TLS when `serverName`, `rootCAs` and
`insecureSkipVerify` are set appropriately
   
**📃 Notes:**

1. Previously service docs were missing any kind of documentation
regarding available integrations. This PR only adds docs about the
traefik integration. Other integrations such as metallb, and cillium
remain undocumented as they are not relevant to this PR.

2. To keep this PR small, I have only added the most commonly used
[ServersTransport configuration
options](https://doc.traefik.io/traefik/reference/routing-configuration/kubernetes/crd/http/serverstransport/#configuration-options).
However, this can easily be extended with more options in the future.

**✔️ Checklist:**

- [X] ⚖️ My code follows the style guidelines of this project
- [X] 👀 I have performed a self-review of my own code
- [X] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [X] 📄 I have made changes to the documentation
- [X] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [X] ⬆️ I increased versions for any altered app according to semantic
versioning
- [X] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or
`fix(docs):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._

---------

Signed-off-by: astro-stan <36302090+astro-stan@users.noreply.github.com>
2025-10-05 22:52:52 +02:00
fc31ef5436 feat(common): Add support for using custom CAs with Volsync (#40000)
**Description**

Allows connecting volsync to an S3 API that uses a self-signed  cert.

Thiis is useful if you are self-hosting an S3 server and you are
exposing it via a self-signed certificate.

In my case this was needed because I am using the LAN IP of the server
and my Let's encrypt cert does not have it as one of its SANs. To avoid
making a LAN IP part of the cert history, I am instead using a
self-signed cert with the IP set up as SAN.

⚒️ Fixes  # <!--(issue)-->

**⚙️ Type of change**

- [X] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] 🔃 Refactor of current code
- [X] 📜 Documentation Changes

**🧪 How Has This Been Tested?**
<!--
Please describe the tests that you ran to verify your changes. Provide
instructions so we can reproduce. Please also list any relevant details
for your test configuration
-->

I rendered the authentik chart with the new common changes and deployed
it manually to my cluster.

What I have tested:

- Output is identical to `master` when `customCA` is unset
- When `customCA` is set to a non-empty string:
- `ReplicationDestination` and `ReplicationSource` resources correctly
render the `customCA` section
- An opaque secret with a single field (`ca.crt`) and name
`<chart-full-name>-volsync-ca-<credentials-name>` is correctly rendered
- The chart installs correctly with `kubectl apply -f
rendered-chart.yml`
- The volsync backup job prints "Using custom CA" and then succeeds in
creating a volume backup of the `blueprints` volume on my self-hosted S3
server with a self-signed cert
 
  
**📃 Notes:**
<!-- Please enter any other relevant information here -->

**✔️ Checklist:**

- [X] ⚖️ My code follows the style guidelines of this project
- [X] 👀 I have performed a self-review of my own code
- [ ] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [X] 📄 I have made changes to the documentation
- [X] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [X] ⬆️ I increased versions for any altered app according to semantic
versioning
- [X] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or
`fix(docs):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._

---------

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2025-09-28 11:29:16 +02:00