knative / knative/serving

Improve TLS conditions on route reconciliation

Open
#15,237 3 comments 0 reactions 1 assignee Claimed by @0xV0YD View on GitHub
area/networking triage/accepted
Dominant language
Go
Stars
6.1k
Forks
1.2k
Avg merge
2d 7h
Merged PRs (30d)
2

Description

Currently the TLS conditions are a bit tricky. We re-use the same condition to reflect the status of `external-domain-tls` and `cluster-local-domain-tls`. The first one also needs considering if an external route actually exists. The proposal now is to:

> Maybe it would be a good idea to introduce another condition to separate cluster-local from external-domain certificates? It's a bit hard to follow that the condition is influenced by two feature flags and if there is actually a route (e.g. external-domain-tls enabled but no external routes and cluster-local-domain-tls disabled). We could even have better messages like
- external-domain-tls: feature is disabled
- external-domain-tls: no certificate required, no external domains found

Original discussion see: https://github.com/knative/serving/pull/15234#issuecomment-2126343951

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.