Fix traefik tls certs during refresh - #879
Thanhphan1147 wants to merge 1 commit into
Conversation
53ec740 to
f8b7da7
Compare
hmlanigan
left a comment
There was a problem hiding this comment.
Question: how do we test this charnge?
a3aa757 to
da500d4
Compare
186ebae to
c08b31d
Compare
|
@Raven-182 I squashed all commits into 1 |
|
@hmlanigan Here are the steps to test the changes ( I tested it on a 1-node sunbeam deployment after enabling tls ca for the public endpoints). The idea is to simulate a replacement of CSR after a leader change for example.
or To only trigger the certificate refresh. Do you think I need to turn this into a doc or integration test? |
|
@Thanhphan1147, the QA steps are for someone to be able to verify the changes in the PR. The tests added should be appropriate for regression. |
|
Hi @gboutry / @hmlanigan, any updated on this? |
The code looks okay to me, we have someone verifying the change now. |
If my understanding is correct, this is an issue when upgrading from speciifc traefik-k8s revision or less. There are already process in place to avoid these kind of issues in future like SolQA tests before traefik-k8s promotion. Adding new command 2025.1 is SLURP release, the chances someone uses sunbeam with 2025.1 is very less Thoughts? |
|
I agree, this should be maintained on the stable version that has a chance to encounter this issue, rather than being maintained on version that will not. |
hemanthnakkina
left a comment
There was a problem hiding this comment.
@Thanhphan1147 Please see the latest comments in conversation
Re-provide stored tls.ca certificates for outstanding CSRs during cluster refresh to recover deployments affected by the traefik certificate bug. Related-PR: https://github.com/canonical/traefik-k8s-operator/pull/729/changes Related-bug: canonical/traefik-k8s-operator#709
fa2faed to
0dd2c96
Compare
|
@hemanthnakkina @gboutry I have removed the |
The release of traefik revision 281 introduces managing certificates in "APP" mode. However, due to an issue with the tls-certiicates library, the corresponding private_key did not had the correct scope, which introduce a risk of service disruption . This PR proposes a fix so that deployments that are in a "degraded" state can self-heal after running the
sunbeam refreshcommand.The PR adds a custom logic towards the end of the
refreshcommand to find outstanding CSRs, check that:sunbeam tls ca unit_certsThen rerun
provide-certifcateaction onmanual-tls-certificatesusing a certificate that matched from the previous step.Assisted-By: copilot
Related-PR: https://github.com/canonical/traefik-k8s-operator/pull/729/changes
Related-bug: canonical/traefik-k8s-operator#709
QA steps
These steps need to be performed on a sunbeam deployment after enabling tls ca for the public endpoints