knative / knative/serving

Design/document the contract for Serving Encryption

Open
#13,819 3 comments 0 reactions 0 assignees View on GitHub
area/networking kind/spec triage/accepted
Dominant language
Go
Stars
6.1k
Forks
1.2k
Avg merge
2d 7h
Merged PRs (30d)
2

Description

## Description
Discuss/design the contract for cluster-local and Knative internal encryption.

## Tasks
- [ ] Draft a design contract for cluster-local and Knative internal encryption with changes to the Knative specification (if needed)
- [ ] Update the Knative specification in code & docs
- [ ] Create/Update conformance tests for networking implementations
- [ ] Add e2e tests in serving to enforce encryption + a full CA rotation

## Related work
- Parent issue: https://github.com/knative/serving/issues/11906
- Findings document: https://docs.google.com/document/d/1YdcdBVg_zpT4WSNRsWlihut5JuLddOTIggFvLni3A28/edit?disco=AAAAtaDADjo

/area networking
/kind spec

Contributor guide

Open the contributing guide

Research direction

Start with the parent issue and the linked findings document to understand the proposed contract for cluster-local and Knative internal encryption. Done means the contract is drafted, the Knative specification and related code/docs are updated, conformance tests cover networking implementations, and Serving has end-to-end encryption and full CA-rotation tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
documentation, networking, security, testing
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.