Skip to content

add tls termination - #2

Merged
bubunyo merged 2 commits into
mainfrom
feat/add-tls-support
Jun 11, 2026
Merged

add tls termination#2
bubunyo merged 2 commits into
mainfrom
feat/add-tls-support

Conversation

@bubunyo

@bubunyo bubunyo commented Jun 11, 2026

Copy link
Copy Markdown
Owner

add tls support

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds optional client-side TLS termination to kroxy’s Kafka listener, configured via YAML and wired through to the proxy server so clients can connect over TLS while the upstream broker connection remains plaintext.

Changes:

  • Introduces tls configuration (enabled/cert_file/key_file) with validation and a Build() helper that loads the server keypair.
  • Wraps the client-facing listener with TLS when configured, and logs whether TLS is enabled.
  • Adds test coverage for TLS handshake + SASL/PLAIN over TLS, plus documentation updates and an example config snippet.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
README.md Documents the new tls config block and updates scope notes to reflect client TLS termination support.
proxy/listener.go Adds TLS wrapping for the client listener and logs TLS enablement.
proxy/listener_tls_test.go Adds integration-style tests for TLS handshake + SASL/PLAIN and plaintext rejection behavior.
dockerfiles/kroxy.yaml Adds commented example tls configuration for the demo stack.
config/config.go Adds TLSConfig, validation, and Build() to produce *tls.Config (or nil when disabled).
config/config_test.go Adds unit tests for TLSConfig.Build() and config validation scenarios.
cmd/kroxy/main.go Wires cfg.TLS.Build() into proxy.NewServer via ServerConfig.TLS.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread proxy/listener.go
@bubunyo
bubunyo merged commit cce194d into main Jun 11, 2026
8 checks passed
@bubunyo
bubunyo deleted the feat/add-tls-support branch June 11, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants