Repository navigation
valkey: enable tls - #4328
valkey: enable tls#4328MustafaSaber wants to merge 2 commits into
Conversation
Allow mTLS connection with valkey - [ ] Add tests - [ ] Support for redis also (another PR) - [ ] Do I need to reload? Signed-off-by: Mustafa Abdelrahman <mustafa.abdelrahman@zalando.de>
|
Docker image "registry-write.opensource.zalan.do/teapot/skipper:71cc3a12e70cae39e624bef4d00305f7c608e0d2" is not based on an approved base image. Any production deployment relying on this image will be blocked. To create a compliant Docker image of your application, you must reference an allowed Docker image as its base image in your Dockerfile. This base image must come from the Zalando Container Registry namespace |
…c to pass to all swarm clients Signed-off-by: Mustafa Abdelrahman <mustafa.abdelrahman@zalando.de>
|
Docker image "registry-write.opensource.zalan.do/teapot/skipper:7f2ea3b3fa445184fe5cbc620abccc10264cbd67" is not based on an approved base image. Any production deployment relying on this image will be blocked. To create a compliant Docker image of your application, you must reference an allowed Docker image as its base image in your Dockerfile. This base image must come from the Zalando Container Registry namespace |
| flag.DurationVar(&cfg.SwarmValkeyKeepAlive, "swarm-valkey-keepalive", net.DefaultKeepAlive, "set valkey keepalive probes interval") | ||
| flag.DurationVar(&cfg.SwarmValkeyUpdateInterval, "swarm-valkey-update-interval", net.DefaultUpdateInterval, "set update interval to update valkey addresses") | ||
| flag.StringVar(&cfg.SwarmClientCertFile, "swarm-client-cert", "", "valkey client certificate") | ||
| flag.StringVar(&cfg.SwarmClientKeyFile, "swarm-client-key", "", "valkey client key") |
There was a problem hiding this comment.
description: swarm client tls key
|
|
||
| ``` | ||
| -swarm-valkey-enable-tls | ||
| -swarm-valkey-client-cert=/path/client.crt |
There was a problem hiding this comment.
-swarm-client-cert as you have in config.go
| cr, err := NewCertReloader(certFile, keyFile, interval, log) | ||
| if err != nil { | ||
| log.Errorf("Failed to initialize cert reloader: %v", err) | ||
| os.Exit(2) |
| Proxy-level config (`EnableMTLS`) presenting a client certificate when connecting to upstream backends, with hot cert rotation. | ||
|
|
||
| **Valkey Swarm mTLS**: | ||
| Mutual-TLS transport between skipper (the client) and a valkey swarm shard: skipper presents a client certificate and verifies the valkey server certificate against a configured CA bundle. Configured via `-swarm-valkey-enable-tls` with a static keypair (no rotation). |
There was a problem hiding this comment.
the option is -swarm-enable-tls and we should always use -enable-X, so -enable-swarm-tls. There is only kubernetes that has a config option that has enable in the middle and most other use -enable-X style:
% bin/skipper -help G -E '[-]enable' master
-access-log-json-enabled
-application-log-json-enabled
-enable-advanced-validation
-enable-api-usage-monitoring
-enable-breakers
-enable-connection-metrics
-enable-copy-stream-pool
-enable-dualstack-backend
-enable-h2c-server
-enable-kubernetes-east-west
-enable-kubernetes-endpointslices
-enable-kubernetes-external-names
-enable-l2-cache
-enable-letsencrypt
-enable-lua
-enable-mtls
-enable-oauth2-grant-flow
-enable-open-policy-agent
-enable-open-policy-agent-async-decision-logging
-enable-open-policy-agent-custom-control-loop
-enable-open-policy-agent-data-preprocessing-optimization
-enable-open-policy-agent-preloading
-enable-open-policy-agent-print-tracing
-enable-profile
-enable-prometheus-metrics
-enable-prometheus-native-histograms
-enable-prometheus-start-label
-enable-proxy-protocol
-enable-ratelimits
-enable-route-fifo-metrics
-enable-route-lifo-metrics
-enable-swarm
-enable-tcp-queue
-kubernetes-enable-tls
-validation-webhook-enabled
Allow mTLS connection with valkey