Is there an existing issue for this?
Current Behavior
GitHub App authentication is a third TLS-dependent operation in the flow of exchanging the App's private key for an installation access token via GitHub's REST API, but it does not consult spec.caBundle at all. It always uses http.DefaultTransport unmodified, so it only ever trusts the host's system CA pool.
This means any environment using GitHub App auth behind an inspecting proxy with a custom/internal CA or any GitHub Enterprise Server instance presenting a certificate not in the system trust store , cannot authenticate.
Expected Behavior
Fleet should respect the spec.caBundle configuration during GitHub App authentication and use the provided CA certificates to verify the TLS connection to the GitHub API.
Steps To Reproduce
- Configure a Kubernetes cluster running Rancher Fleet behind an outbound proxy using a custom CA.
- Apply a Fleet GitRepo resource configured with GitHub App authentication and set spec.caBundle to the custom CA certificate
- Trigger a synchronization/cloning job for the repository.
Environment
Logs
could not authenticate as GitHub App installation: could not refresh installation id <id>'s token: could not get access_tokens from GitHub API for installation ID <id>: tls: failed to verify certificate: x509: certificate signed by unknown authority
Anything else?
No response
Is there an existing issue for this?
Current Behavior
GitHub App authentication is a third TLS-dependent operation in the flow of exchanging the App's private key for an installation access token via GitHub's REST API, but it does not consult spec.caBundle at all. It always uses http.DefaultTransport unmodified, so it only ever trusts the host's system CA pool.
This means any environment using GitHub App auth behind an inspecting proxy with a custom/internal CA or any GitHub Enterprise Server instance presenting a certificate not in the system trust store , cannot authenticate.
Expected Behavior
Fleet should respect the spec.caBundle configuration during GitHub App authentication and use the provided CA certificates to verify the TLS connection to the GitHub API.
Steps To Reproduce
Environment
Logs
Anything else?
No response