Skip to content

Fix traefik tls certs during refresh - #879

Open
Thanhphan1147 wants to merge 1 commit into
canonical:stable/2024.1from
Thanhphan1147:fix-traefik-tls-certs
Open

Thanhphan1147 wants to merge 1 commit into
canonical:stable/2024.1from
Thanhphan1147:fix-traefik-tls-certs

Conversation

@Thanhphan1147

@Thanhphan1147 Thanhphan1147 commented Jul 9, 2026 •

Copy link
Copy Markdown

The release of traefik revision 281 introduces managing certificates in "APP" mode. However, due to an issue with the tls-certiicates library, the corresponding private_key did not had the correct scope, which introduce a risk of service disruption . This PR proposes a fix so that deployments that are in a "degraded" state can self-heal after running the sunbeam refresh command.

The PR adds a custom logic towards the end of the refresh command to find outstanding CSRs, check that:

  1. The subject matches the certificates provided by the operator via sunbeam tls ca unit_certs
  2. The public key of the certificate matches the outstanding CSR
  3. The certificate has not expired

Then rerun provide-certifcate action on manual-tls-certificates using a certificate that matched from the previous step.

Assisted-By: copilot

Related-PR: https://github.com/canonical/traefik-k8s-operator/pull/729/changes
Related-bug: canonical/traefik-k8s-operator#709

QA steps

These steps need to be performed on a sunbeam deployment after enabling tls ca for the public endpoints

  1. Save the current private key
TLS_KEY_SECRET_ID=$(juju secrets --format yaml | python3 -c "
import sys,yaml
s=yaml.safe_load(sys.stdin)
[print(k) for k,v in s.items() if v.get(label)==tls-key]")

juju show-secret ${TLS_KEY_SECRET_ID} --reveal --format yaml \
    | python3 -c "
import sys,yaml,json
d=list(yaml.safe_load(sys.stdin).values())[0]
yaml.dump({private-keys:d[content][private-keys]},open(/tmp/orig.yaml,w))"
  1. Replace the current private key with a random one ( we'll throw it away later, it's just to simulate a replacement of the CSR )
juju update-secret ${TLS_KEY_SECRET_ID} --file /tmp/new_tls_key.yaml
jhack fire traefik-public/0 config-changed
sleep 15
  1. Restore the original key
juju update-secret ${TLS_KEY_SECRET_ID} --file /tmp/orig.yaml
jhack fire traefik-public/0 config-changed
sleep 15
  1. Re-provide certificate
openstack.sunbeam cluster refresh

@Thanhphan1147
Thanhphan1147 marked this pull request as ready for review July 10, 2026 05:29
@Thanhphan1147
Thanhphan1147 force-pushed the fix-traefik-tls-certs branch from 53ec740 to f8b7da7 Compare July 10, 2026 05:44
@Thanhphan1147 Thanhphan1147 changed the title Fix traefik tls certs Fix traefik tls certs during refresh Jul 10, 2026

@hmlanigan hmlanigan left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Question: how do we test this charnge?

Comment thread sunbeam-python/sunbeam/commands/refresh.py Outdated
Comment thread sunbeam-python/tests/unit/sunbeam/features/test_tls.py

@Raven-182 Raven-182 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the patch. Some comments:

Comment thread sunbeam-python/sunbeam/features/tls/ca.py Outdated
@Thanhphan1147
Thanhphan1147 force-pushed the fix-traefik-tls-certs branch from a3aa757 to da500d4 Compare July 16, 2026 01:07
Comment thread sunbeam-python/sunbeam/features/tls/ca.py Outdated
Comment thread sunbeam-python/sunbeam/features/tls/ca.py Outdated
@Thanhphan1147

Copy link
Copy Markdown
Author

@Raven-182 I squashed all commits into 1

@Thanhphan1147

Copy link
Copy Markdown
Author

@hmlanigan Here are the steps to test the changes ( I tested it on a 1-node sunbeam deployment after enabling tls ca for the public endpoints). The idea is to simulate a replacement of CSR after a leader change for example.

  1. Save the current private key
TLS_KEY_SECRET_ID=$(juju secrets --format yaml | python3 -c "
import sys,yaml
s=yaml.safe_load(sys.stdin)
[print(k) for k,v in s.items() if v.get('label')=='tls-key']")

juju show-secret ${TLS_KEY_SECRET_ID} --reveal --format yaml \
    | python3 -c "
import sys,yaml,json
d=list(yaml.safe_load(sys.stdin).values())[0]
yaml.dump({'private-keys':d['content']['private-keys']},open('/tmp/orig.yaml','w'))"
  1. Replace the current private key with a random one ( we'll throw it away later, it's just to simulate a replacement of the CSR )
juju update-secret ${TLS_KEY_SECRET_ID} --file /tmp/new_tls_key.yaml
jhack fire traefik-public/0 config-changed
sleep 15
  1. Restore the original key
juju update-secret ${TLS_KEY_SECRET_ID} --file /tmp/orig.yaml
jhack fire traefik-public/0 config-changed
sleep 15
  1. Re-provide certificate
openstack.sunbeam cluster refresh

or

openstack.sunbeam cluster refresh certificates

To only trigger the certificate refresh.

Do you think I need to turn this into a doc or integration test?

@hmlanigan

Copy link
Copy Markdown

@Thanhphan1147, the QA steps are for someone to be able to verify the changes in the PR. The tests added should be appropriate for regression.

@Thanhphan1147

Copy link
Copy Markdown
Author

Hi @gboutry / @hmlanigan, any updated on this?

@hemanthnakkina
hemanthnakkina self-requested a review September 2, 2026 09:22
@hmlanigan

Copy link
Copy Markdown

Hi @gboutry / @hmlanigan, any updated on this?

The code looks okay to me, we have someone verifying the change now.

@hemanthnakkina

Copy link
Copy Markdown
Collaborator

Hi @gboutry / @hmlanigan, any updated on this?

The code looks okay to me, we have someone verifying the change now.

If my understanding is correct, this is an issue when upgrading from speciifc traefik-k8s revision or less. There are already process in place to avoid these kind of issues in future like SolQA tests before traefik-k8s promotion.

Adding new command sunbeam cluster refresh certificates does not make sense.
I think it is enough to handle this in sunbeam cluster refresh ONLY for stable/2024.1 branch

2025.1 is SLURP release, the chances someone uses sunbeam with 2025.1 is very less
2026.1 is not yet released

Thoughts?

@gboutry

gboutry commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator

I agree, this should be maintained on the stable version that has a chance to encounter this issue, rather than being maintained on version that will not.

@hemanthnakkina hemanthnakkina left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Thanhphan1147 Please see the latest comments in conversation

@Thanhphan1147
Thanhphan1147 changed the base branch from main to stable/2024.1 September 21, 2026 08:07
Re-provide stored tls.ca certificates for outstanding CSRs during
cluster refresh to recover deployments affected by the traefik
certificate bug.

Related-PR: https://github.com/canonical/traefik-k8s-operator/pull/729/changes
Related-bug: canonical/traefik-k8s-operator#709
@Thanhphan1147

Copy link
Copy Markdown
Author

@hemanthnakkina @gboutry I have removed the sunbeam cluster refresh certificates command and kept the logic only in sunbeam cluster refresh. I have also rebased the branch on top of stable/2024.1 and squashed the commits into a single commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants