zalando / zalando/postgres-operator
TLS certs only readable by root
Open
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 5.2k
- Forks
- 1.1k
- Avg merge
- 2d 16h
- Merged PRs (30d)
- 3
Description
Please, answer some short questions which should help us to understand your problem / question better?
- Which image of the operator are you using? e.g. registry.opensource.zalan.do/acid/postgres-operator:v1.6.1
- Where do you run it - cloud or metal? Kubernetes or OpenShift? Bare Metal K8s
- Are you running Postgres Operator in production? no
- Type of issue? Bug report
PostgreSQL can't read the TLS certificate and key provided by cluster configuration:
tls:
secretName: my-tls-secret
# ls -l /tls
total 0
lrwxrwxrwx 1 root root 14 Mar 16 09:18 tls.crt -> ..data/tls.crt
lrwxrwxrwx 1 root root 14 Mar 16 09:18 tls.key -> ..data/tls.key
# ls -l /tls/..data/
total 8
-rw-r----- 1 root root 1135 Mar 16 09:18 tls.crt
-rw-r----- 1 root root 1704 Mar 16 09:18 tls.key
FATAL: could not load server certificate file "/tls/tls.crt": Permission denied
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing how the operator mounts the configured my-tls-secret into /tls and how Kubernetes sets the certificate and key permissions. Reproduce the Bare Metal K8s setup, then verify that PostgreSQL can read /tls/tls.crt and /tls/tls.key without the shown permission error.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes, postgresql
- Domain
- databases, infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100