04b47b8a4ff4dd72e51e572e26c68e41ce15222e
3
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
c0ff8684ce |
feat(common): Add support for secretRefs when defining custom CA for use with S3 credentials (#40385)
**Description** This PR builds up on #40000 by adding an additional key - `credentials.$name.customCASecretRef`. This allows referencing secrets via the already familiar `configMapRef`/`secretRef` pattern, using the `name` and `expandObjectName` keys to reference secrets defined under `.Values.secret`. Additionally, it also adds a `credentials.$name.customCASecretRef.key` forcing users to specify the key in the secret which contains the CA, for maximum flexibility. ⚒️ Fixes # <!--(issue)--> **⚙️ Type of change** - [X] ⚙️ Feature/App addition - [ ] 🪛 Bugfix - [ ] ⚠️ Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] 🔃 Refactor of current code - [X] 📜 Documentation Changes **🧪 How Has This Been Tested?** <!-- Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration --> I tested rendering the same CA secret using both the current `customCA` implementation and the new `.secret.$name` + `customCASecretRef` way. Also added unit tests for CI. **📃 Notes:** Regarding CNPG support - the changes in this PR and from #40000 should also work for CNPG. As far as i can tell it requires the CA secret to be referenced under a key called `endpointCA` in the following way ([docs](https://cloudnative-pg.io/documentation/1.16/api_reference/#backupstatus), [CRD def](https://github.com/cloudnative-pg/cloudnative-pg/blob/6ae2fb61bee4f959545bceeacfc5a209b2358668/config/crd/bases/postgresql.cnpg.io_backups.yaml#L256)): ```yaml ... barmanObjectStore: endpointURL: ... ... endpointCA: name: secret-name key: secret-key ``` Note that while the current [in-tree barman cloud support is being deprecated in favour of a barman cloud plugin](https://cloudnative-pg.io/releases/cloudnative-pg-1-26.0-released/#barman-cloud-deprecation-begins), the [migration guide](https://cloudnative-pg.io/plugin-barman-cloud/docs/migration/) says the new `ObjectStore` CRD has a **direct mapping** between it and the legacy `barmanObjectStore`. Therefore, the example above can be translated to: ```yaml apiVersion: barmancloud.cnpg.io/v1 kind: ObjectStore ... spec: configuration: endpointURL: ... ... endpointCA: name: secret-name key: secret-key ``` **✔️ Checklist:** - [X] ⚖️ My code follows the style guidelines of this project - [X] 👀 I have performed a self-review of my own code - [X] #️⃣ I have commented my code, particularly in hard-to-understand areas - [X] 📄 I have made changes to the documentation - [X] 🧪 I have added tests to this description that prove my fix is effective or that my feature works - [X] ⬆️ I increased versions for any altered app according to semantic versioning - [X] I made sure the title starts with `feat(chart-name):`, `fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or `fix(docs):` **➕ App addition** If this PR is an app addition please make sure you have done the following. - [ ] 🖼️ I have added an icon in the Chart's root directory called `icon.png` --- _Please don't blindly check all the boxes. Read them and only check those that apply. Those checkboxes are there for the reviewer to see what is this all about and the status of this PR with a quick glance._ --------- Signed-off-by: Kjeld Schouten <info@kjeldschouten.nl> Co-authored-by: Kjeld Schouten <info@kjeldschouten.nl> |
||
|
|
9ff148b37a |
feat(common): Improve traefik service integration (#40293)
**Description** This PR improves the traefik service integration by: - Adds ability to generate [ServersTransport](https://doc.traefik.io/traefik/reference/routing-configuration/kubernetes/crd/http/serverstransport/) resources - Adds docs regarding the traefik service integration to the website ⚒️ Fixes # NA **⚙️ Type of change** - [X] ⚙️ Feature/App addition - [ ] 🪛 Bugfix - [ ] ⚠️ Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] 🔃 Refactor of current code - [X] 📜 Documentation Changes **🧪 How Has This Been Tested?** What I have tested: - ServersTransport generation - `traefik.ingress.kubernetes.io/service.serversscheme` and `traefik.ingress.kubernetes.io/service.serverstransport` service annotations generation - Traefik: - talks over HTTPS when `traefik.ingress.kubernetes.io/service.serversscheme: "https"` is set on the service - skips TLS verification when `insecureSkipVerify: true` - Successfully verifies TLS when `serverName`, `rootCAs` and `insecureSkipVerify` are set appropriately **📃 Notes:** 1. Previously service docs were missing any kind of documentation regarding available integrations. This PR only adds docs about the traefik integration. Other integrations such as metallb, and cillium remain undocumented as they are not relevant to this PR. 2. To keep this PR small, I have only added the most commonly used [ServersTransport configuration options](https://doc.traefik.io/traefik/reference/routing-configuration/kubernetes/crd/http/serverstransport/#configuration-options). However, this can easily be extended with more options in the future. **✔️ Checklist:** - [X] ⚖️ My code follows the style guidelines of this project - [X] 👀 I have performed a self-review of my own code - [X] #️⃣ I have commented my code, particularly in hard-to-understand areas - [X] 📄 I have made changes to the documentation - [X] 🧪 I have added tests to this description that prove my fix is effective or that my feature works - [X] ⬆️ I increased versions for any altered app according to semantic versioning - [X] I made sure the title starts with `feat(chart-name):`, `fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or `fix(docs):` **➕ App addition** If this PR is an app addition please make sure you have done the following. - [ ] 🖼️ I have added an icon in the Chart's root directory called `icon.png` --- _Please don't blindly check all the boxes. Read them and only check those that apply. Those checkboxes are there for the reviewer to see what is this all about and the status of this PR with a quick glance._ --------- Signed-off-by: astro-stan <36302090+astro-stan@users.noreply.github.com> |
||
|
|
fc31ef5436 |
feat(common): Add support for using custom CAs with Volsync (#40000)
**Description** Allows connecting volsync to an S3 API that uses a self-signed cert. Thiis is useful if you are self-hosting an S3 server and you are exposing it via a self-signed certificate. In my case this was needed because I am using the LAN IP of the server and my Let's encrypt cert does not have it as one of its SANs. To avoid making a LAN IP part of the cert history, I am instead using a self-signed cert with the IP set up as SAN. ⚒️ Fixes # <!--(issue)--> **⚙️ Type of change** - [X] ⚙️ Feature/App addition - [ ] 🪛 Bugfix - [ ] ⚠️ Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] 🔃 Refactor of current code - [X] 📜 Documentation Changes **🧪 How Has This Been Tested?** <!-- Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration --> I rendered the authentik chart with the new common changes and deployed it manually to my cluster. What I have tested: - Output is identical to `master` when `customCA` is unset - When `customCA` is set to a non-empty string: - `ReplicationDestination` and `ReplicationSource` resources correctly render the `customCA` section - An opaque secret with a single field (`ca.crt`) and name `<chart-full-name>-volsync-ca-<credentials-name>` is correctly rendered - The chart installs correctly with `kubectl apply -f rendered-chart.yml` - The volsync backup job prints "Using custom CA" and then succeeds in creating a volume backup of the `blueprints` volume on my self-hosted S3 server with a self-signed cert **📃 Notes:** <!-- Please enter any other relevant information here --> **✔️ Checklist:** - [X] ⚖️ My code follows the style guidelines of this project - [X] 👀 I have performed a self-review of my own code - [ ] #️⃣ I have commented my code, particularly in hard-to-understand areas - [X] 📄 I have made changes to the documentation - [X] 🧪 I have added tests to this description that prove my fix is effective or that my feature works - [X] ⬆️ I increased versions for any altered app according to semantic versioning - [X] I made sure the title starts with `feat(chart-name):`, `fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or `fix(docs):` **➕ App addition** If this PR is an app addition please make sure you have done the following. - [ ] 🖼️ I have added an icon in the Chart's root directory called `icon.png` --- _Please don't blindly check all the boxes. Read them and only check those that apply. Those checkboxes are there for the reviewer to see what is this all about and the status of this PR with a quick glance._ --------- Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com> Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com> |