Skip to content

ADR: CA bundle injection for webhooks - #522

Merged
adwk67 merged 30 commits into
mainfrom
adr-foundation-webhoos-ca-injection
Mar 6, 2024
Merged

adwk67 merged 30 commits into
mainfrom
adr-foundation-webhoos-ca-injection

Conversation

@maltesander

@maltesander maltesander commented Jan 9, 2024 •

Copy link
Copy Markdown
Member

Refinement 05.02.2024

  • On OpenShift, OLM deployments manages CAs it's self
  • We don't consider it acceptable to require customers to manage a Cert Manager deployment just for the purpose of registering webhooks.
  • We need to have a feature flag that can be turned off on platforms that manage CAs themselves.
  • Make the key reader configurable because there may be different key formats. The OLM spike has shown that OLM generates keys in ec format.

preview link: https://deploy-preview-522--stackable-docs.netlify.app/home/nightly/contributor/adr/adr033-foundation-webhooks-ca-bundle

@netlify

netlify Bot commented Jan 9, 2024 •

Copy link
Copy Markdown

✅ Deploy Preview for stackable-docs ready!

Name Link
🔨 Latest commit f10f009
🔍 Latest deploy log https://app.netlify.com/sites/stackable-docs/deploys/65d89fc2b1b2010008369903
😎 Deploy Preview https://deploy-preview-522--stackable-docs.netlify.app/home/nightly/contributor/adr/adr033-foundation-webhooks-ca-bundle
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
maltesander and others added 2 commits January 9, 2024 15:03
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
@maltesander
maltesander marked this pull request as ready for review January 22, 2024 13:16
adwk67
adwk67 previously approved these changes Jan 22, 2024

@adwk67 adwk67 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm! Just a few minor suggestions.

Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Co-authored-by: Andrew Kenworthy <andrew.kenworthy@stackable.de>
@maltesander
maltesander requested a review from adwk67 January 22, 2024 16:41
…ndle.adoc

Co-authored-by: Andrew Kenworthy <andrew.kenworthy@stackable.de>
adwk67
adwk67 previously approved these changes Jan 22, 2024

@adwk67 adwk67 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@razvan razvan left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

my 2€ cents

Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated
@maltesander
maltesander requested a review from razvan January 31, 2024 14:45
maltesander and others added 2 commits January 31, 2024 17:17
Co-authored-by: Razvan-Daniel Mihai <84674+razvan@users.noreply.github.com>
@razvan

razvan commented Feb 2, 2024

Copy link
Copy Markdown
Member

More on OLM : according to the documentation, OLM does it's own CA injection:

OLM is configured to provide each deployment with a single certificate authority (CA). The logic that generates and mounts the CA into the deployment was originally used by the API service lifecycle logic. As a result:

  • The TLS certificate file is mounted to the deployment at /apiserver.local.config/certificates/apiserver.crt.
  • The TLS key file is mounted to the deployment at /apiserver.local.config/certificates/apiserver.key.

How will this affect our approach ?

@razvan

razvan commented Feb 8, 2024 •

Copy link
Copy Markdown
Member

More on OLM : according to the documentation, OLM does it's own CA injection:
...
How will this affect our approach ?

To answer my own question, after spiking a dummy webhook with the secret op on OLM: we should not do CA bundle injection on OLM.

Also I think as part of the foundation work, this ADR should describe what kind of configuation triggers the secret op to do CA injection.

Comment thread modules/contributor/pages/adr/ADR033-foundation-webhooks-ca-bundle.adoc Outdated

@Techassi Techassi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is in a mergeable state. Fine adjustments (like adding further details) can be added at a later point in time.

@adwk67
adwk67 added this pull request to the merge queue Mar 6, 2024
Merged via the queue into main with commit a96772c Mar 6, 2024
@adwk67
adwk67 deleted the adr-foundation-webhoos-ca-injection branch March 6, 2024 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

5 participants