Skip to content

valkey: enable tls - #4328

Draft
MustafaSaber wants to merge 2 commits into
masterfrom
skipper-valkey-tls
Draft

MustafaSaber wants to merge 2 commits into
masterfrom
skipper-valkey-tls

Conversation

@MustafaSaber

Copy link
Copy Markdown
Collaborator

Allow mTLS connection with valkey

  • Add tests
  • Support for redis also (another PR)
  • Do I need to reload?

Allow mTLS connection with valkey

- [ ] Add tests
- [ ] Support for redis also (another PR)
- [ ] Do I need to reload?

Signed-off-by: Mustafa Abdelrahman <mustafa.abdelrahman@zalando.de>
@MustafaSaber MustafaSaber added the major moderate risk, for example new API, small filter changes that have no risk like refactoring or logs label Oct 8, 2026
@zalando-robot

Copy link
Copy Markdown

Docker image "registry-write.opensource.zalan.do/teapot/skipper:71cc3a12e70cae39e624bef4d00305f7c608e0d2" is not based on an approved base image. Any production deployment relying on this image will be blocked.

To create a compliant Docker image of your application, you must reference an allowed Docker image as its base image in your Dockerfile. This base image must come from the Zalando Container Registry namespace library and use a recommended version as listed in the documentation.

…c to pass to all swarm clients

Signed-off-by: Mustafa Abdelrahman <mustafa.abdelrahman@zalando.de>
@zalando-robot

Copy link
Copy Markdown

Docker image "registry-write.opensource.zalan.do/teapot/skipper:7f2ea3b3fa445184fe5cbc620abccc10264cbd67" is not based on an approved base image. Any production deployment relying on this image will be blocked.

To create a compliant Docker image of your application, you must reference an allowed Docker image as its base image in your Dockerfile. This base image must come from the Zalando Container Registry namespace library and use a recommended version as listed in the documentation.

Comment thread config/config.go
flag.DurationVar(&cfg.SwarmValkeyKeepAlive, "swarm-valkey-keepalive", net.DefaultKeepAlive, "set valkey keepalive probes interval")
flag.DurationVar(&cfg.SwarmValkeyUpdateInterval, "swarm-valkey-update-interval", net.DefaultUpdateInterval, "set update interval to update valkey addresses")
flag.StringVar(&cfg.SwarmClientCertFile, "swarm-client-cert", "", "valkey client certificate")
flag.StringVar(&cfg.SwarmClientKeyFile, "swarm-client-key", "", "valkey client key")

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

description: swarm client tls key


```
-swarm-valkey-enable-tls
-swarm-valkey-client-cert=/path/client.crt

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

-swarm-client-cert as you have in config.go

Comment thread net/httpclient.go
cr, err := NewCertReloader(certFile, keyFile, interval, log)
if err != nil {
log.Errorf("Failed to initialize cert reloader: %v", err)
os.Exit(2)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why not log.Fatalf ?

Comment thread CONTEXT.md
Proxy-level config (`EnableMTLS`) presenting a client certificate when connecting to upstream backends, with hot cert rotation.

**Valkey Swarm mTLS**:
Mutual-TLS transport between skipper (the client) and a valkey swarm shard: skipper presents a client certificate and verifies the valkey server certificate against a configured CA bundle. Configured via `-swarm-valkey-enable-tls` with a static keypair (no rotation).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the option is -swarm-enable-tls and we should always use -enable-X, so -enable-swarm-tls. There is only kubernetes that has a config option that has enable in the middle and most other use -enable-X style:

% bin/skipper -help G -E '[-]enable'                                                                                                                                            master
  -access-log-json-enabled
  -application-log-json-enabled
  -enable-advanced-validation
  -enable-api-usage-monitoring
  -enable-breakers
  -enable-connection-metrics
  -enable-copy-stream-pool
  -enable-dualstack-backend
  -enable-h2c-server
  -enable-kubernetes-east-west
  -enable-kubernetes-endpointslices
  -enable-kubernetes-external-names
  -enable-l2-cache
  -enable-letsencrypt
  -enable-lua
  -enable-mtls
  -enable-oauth2-grant-flow
  -enable-open-policy-agent
  -enable-open-policy-agent-async-decision-logging
  -enable-open-policy-agent-custom-control-loop
  -enable-open-policy-agent-data-preprocessing-optimization
  -enable-open-policy-agent-preloading
  -enable-open-policy-agent-print-tracing
  -enable-profile
  -enable-prometheus-metrics
  -enable-prometheus-native-histograms
  -enable-prometheus-start-label
  -enable-proxy-protocol
  -enable-ratelimits
  -enable-route-fifo-metrics
  -enable-route-lifo-metrics
  -enable-swarm
  -enable-tcp-queue
  -kubernetes-enable-tls
  -validation-webhook-enabled

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation major moderate risk, for example new API, small filter changes that have no risk like refactoring or logs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants