Resolve listener TLS certificates through an extension server - #10142
Open
wweiwei-li wants to merge 7 commits into
Open
wweiwei-li wants to merge 7 commits into
wweiwei-li wants to merge 7 commits into
Conversation
…urces Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
…ificates Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
✅ Deploy Preview for cerulean-figolla-1f9435 ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #10142 +/- ##
==========================================
- Coverage 81.41% 81.36% -0.06%
==========================================
Files 266 266
Lines 41300 41567 +267
==========================================
+ Hits 33626 33819 +193
- Misses 7673 7747 +74
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
feat: resolve listener TLS certificates through an extension server
What this PR does / why we need it:
Envoy Gateway can only source listener TLS certificates from Kubernetes Secrets today. This PR lets an extension server supply them, so certificates managed outside of Secrets (for example, issued and rotated by an external provider) can back a Gateway listener.
An extension registers one or more certificate kinds via a new
ExtensionManager.CertificateResourcesfield. A listener'stls.certificateRefsmay then point at a resource of a registered kind. During xDS translation, Envoy Gateway calls a newPostTLSCertificateResolvehook on the owning extension, which returns how Envoy should obtain the certificate (anSdsSecretConfig, resolved by name or served over SDS). The resolved config is wired into the listener's TLS transport socket.The change is layered so each concern is reviewable on its own:
ExtensionManager.CertificateResourcesand theTLSCertificatetranslator-hook enum value; validation requires theTLSCertificatehook whencertificateResourcesis set.PostTLSCertificateResolveRPC and the corresponding hook. The hook is non-chaining — a certificate kind is owned by exactly one extension, selected by the referenced resource's group/kind.TLSCertificate.ExtensionRefso an extension-resolved certificate can be represented without key material.Behavior for existing configurations is unchanged: listeners that use only Secret-backed certificates never touch the extension path.
Which issue(s) this PR fixes:
#10008
PR Checklist
git commit -s). See DCO: Sign your work./api), the API was discussed and agreed before the implementation. The API change can be in a separate PR, or in the same PR, but the API must be agreed before implementation. N/A if this PR does not contain API changes.make generate gen-check,make lint, and the unit-test/coverage build pass. (Flaky e2e failures are not considered breakages, butgen-check,lint, and coverage MUST pass.)release-notes/current/<section>/<pr-number>-<slug>.md(seerelease-notes/current/README.mdfor sections and naming). N/A if this PR does not contain non-trivial changes.make gen-checkand committed the result if API/helm charts/modules changed.release-notes/current/breaking_changes/.