Skip to content

Resolve listener TLS certificates through an extension server - #10142

Open
wweiwei-li wants to merge 7 commits into
envoyproxy:mainfrom
wweiwei-li:cert-extension-eg
Open

wweiwei-li wants to merge 7 commits into
envoyproxy:mainfrom
wweiwei-li:cert-extension-eg

Conversation

@wweiwei-li

Copy link
Copy Markdown
Contributor

feat: resolve listener TLS certificates through an extension server

What this PR does / why we need it:

Envoy Gateway can only source listener TLS certificates from Kubernetes Secrets today. This PR lets an extension server supply them, so certificates managed outside of Secrets (for example, issued and rotated by an external provider) can back a Gateway listener.

An extension registers one or more certificate kinds via a new ExtensionManager.CertificateResources field. A listener's tls.certificateRefs may then point at a resource of a registered kind. During xDS translation, Envoy Gateway calls a new
PostTLSCertificateResolve hook on the owning extension, which returns how Envoy should obtain the certificate (an SdsSecretConfig, resolved by name or served over SDS). The resolved config is wired into the listener's TLS transport socket.

The change is layered so each concern is reviewable on its own:

  • api: add ExtensionManager.CertificateResources and the TLSCertificate translator-hook enum value; validation requires the TLSCertificate hook when certificateResources is set.
  • proto / extension: add the PostTLSCertificateResolve RPC and the corresponding hook. The hook is non-chaining — a certificate kind is owned by exactly one extension, selected by the referenced resource's group/kind.
  • ir: add TLSCertificate.ExtensionRef so an extension-resolved certificate can be represented without key material.
  • gatewayapi: validate the certificate ref against registered kinds and a ReferenceGrant, and thread the referenced resource into the IR.
  • xds/translator: resolve each extension certificate through the hook and build the SDS config. A listener whose certificates are all extension-provided and none resolve is skipped rather than emitting a certificate-less filter chain
  • provider/kubernetes: watch and list the registered certificate kinds and add them to the resource tree. The watch intentionally omits the generation-change filter so a status-only update from the provider (for example, a certificate becoming ready) retriggers resolution.

Behavior for existing configurations is unchanged: listeners that use only Secret-backed certificates never touch the extension path.

Which issue(s) this PR fixes:

#10008


PR Checklist

  • Authorship & ownership: Coding agents / AI assistants are welcome, but I have reviewed every change, understand how and why it works, can explain and maintain it, and take full responsibility for this PR. I have not submitted generated output I do not understand.
  • DCO: All commits are signed off (git commit -s). See DCO: Sign your work.
  • API agreed first: If this PR contains API changes (changes under /api), the API was discussed and agreed before the implementation. The API change can be in a separate PR, or in the same PR, but the API must be agreed before implementation. N/A if this PR does not contain API changes.
  • [x ] Required checks pass: make generate gen-check, make lint, and the unit-test/coverage build pass. (Flaky e2e failures are not considered breakages, but gen-check, lint, and coverage MUST pass.)
  • Tests added/updated: New/changed code is covered by appropriate tests. N/A if this PR does not contain code changes.
  • Docs: User-facing changes update the docs, either in this PR or a follow-up PR. N/A if this PR does not contain user-facing changes.
  • Release notes: For any non-trivial change, added a release-note fragment under release-notes/current/<section>/<pr-number>-<slug>.md (see release-notes/current/README.md for sections and naming). N/A if this PR does not contain non-trivial changes.
  • Generated files committed: Ran make gen-check and committed the result if API/helm charts/modules changed.
  • Scope & compatibility: The PR is reasonably scoped (no unrelated changes) and preserves backward compatibility, or any breaking change is called out above and documented in release-notes/current/breaking_changes/.
  • Codex review: Requested a Codex review and addressed all of its comments.
  • Copilot review: Requested a Copilot review and addressed all of its comments.

…urces

Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
…ificates

Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
Signed-off-by: Weiwei Li <weiweiww@amazon.com>
@wweiwei-li
wweiwei-li requested a review from a team as a code owner September 29, 2026 03:06
@netlify

netlify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for cerulean-figolla-1f9435 ready!

Name Link
🔨 Latest commit 91b46bb
🔍 Latest deploy log https://app.netlify.com/projects/cerulean-figolla-1f9435/deploys/6abb2b55def2b000084d1577
😎 Deploy Preview https://deploy-preview-10142--cerulean-figolla-1f9435.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 68.75000% with 90 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.36%. Comparing base (f1f4888) to head (91b46bb).

Files with missing lines Patch % Lines
internal/provider/kubernetes/controller.go 17.07% 34 Missing ⚠️
internal/gatewayapi/validate.go 58.33% 25 Missing ⚠️
internal/xds/translator/listener.go 87.50% 8 Missing ⚠️
internal/extension/registry/xds_hook.go 84.00% 4 Missing ⚠️
internal/gatewayapi/runner/runner.go 0.00% 4 Missing ⚠️
internal/xds/translator/translator.go 80.00% 4 Missing ⚠️
...ternal/extension/registry/composite_hook_client.go 76.92% 3 Missing ⚠️
internal/ir/xds.go 62.50% 3 Missing ⚠️
internal/provider/kubernetes/controller_offline.go 70.00% 3 Missing ⚠️
internal/gatewayapi/listener.go 33.33% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main   #10142      +/-   ##
==========================================
- Coverage   81.41%   81.36%   -0.06%     
==========================================
  Files         266      266              
  Lines       41300    41567     +267     
==========================================
+ Hits        33626    33819     +193     
- Misses       7673     7747      +74     
  Partials        1        1              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant