Skip to content

[SURE-12041] GitHub App authentication does not respect spec.caBundle, causing x509: certificate signed by unknown authority behind an inspecting proxy or custom CA #5738

Description

@rajeshkio

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

GitHub App authentication is a third TLS-dependent operation in the flow of exchanging the App's private key for an installation access token via GitHub's REST API, but it does not consult spec.caBundle at all. It always uses http.DefaultTransport unmodified, so it only ever trusts the host's system CA pool.

This means any environment using GitHub App auth behind an inspecting proxy with a custom/internal CA or any GitHub Enterprise Server instance presenting a certificate not in the system trust store , cannot authenticate.

Expected Behavior

Fleet should respect the spec.caBundle configuration during GitHub App authentication and use the provided CA certificates to verify the TLS connection to the GitHub API.

Steps To Reproduce

  • Configure a Kubernetes cluster running Rancher Fleet behind an outbound proxy using a custom CA.
  • Apply a Fleet GitRepo resource configured with GitHub App authentication and set spec.caBundle to the custom CA certificate
  • Trigger a synchronization/cloning job for the repository.

Environment

Fleet v0.3.10

Logs

could not authenticate as GitHub App installation: could not refresh installation id <id>'s token: could not get access_tokens from GitHub API for installation ID <id>: tls: failed to verify certificate: x509: certificate signed by unknown  authority

Anything else?

No response

Activity

  1. added a commit that references this issue on Sep 10, 2026
    14f5ba8
  2. added theissue type on Sep 17, 2026
  3. changed the title [-]GitHub App authentication does not respect spec.caBundle, causing x509: certificate signed by unknown authority behind an inspecting proxy or custom CA[/-] [+][SURE-12041] GitHub App authentication does not respect spec.caBundle, causing x509: certificate signed by unknown authority behind an inspecting proxy or custom CA[/+] on Sep 17, 2026
  4. moved this from 🆕 New to To Triage in Fleeton Sep 17, 2026
  5. moved this from To Triage to 👀 In review in Fleeton Sep 23, 2026
  6. added this to the v2.16.1 milestone on Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    • Status
      👀 In review

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions