cockroachdb / cockroachdb/cockroach-operator
tls.crt and tls.key shouldn't be hardcoded for nodeTLSSecret
- Lenguaje dominante
- Go
- Estrellas
- 318
- Forks
- 104
- Merge medio
- 1 d 6 h
- PR fusionados (30 d)
- 1
Descripción
According to @keith-mcclellan, the API currently requires the filenames `tls.crt` and `tls.key`.
```
nodeTLSSecret:
description: '(Optional) The secret with certificates and a private
key for the TLS endpoint on the database port. The standard naming
of files is expected (tls.key, tls.crt, ca.crt) Default: ""'
type: string
```
When creating and signing certs with `cockroach cert create-node`, we have to manually rename the generated `node.crt` and `node.key` to those filenames in order for authentication to work. This is a less-than-ideal user experience.
`nodeTLSSecret` should be able to accept the `node.crt` and `node.key` generated by Cockroach.
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.