Skip to content

DNM: proof of concept for self-signed cert volume mount #186

Draft
deer-wmde wants to merge 1 commit intomainfrom
de/self-signed-ssl-poc
Draft

DNM: proof of concept for self-signed cert volume mount #186
deer-wmde wants to merge 1 commit intomainfrom
de/self-signed-ssl-poc

Conversation

@deer-wmde
Copy link
Contributor

@deer-wmde deer-wmde commented Feb 12, 2025

https://phabricator.wikimedia.org/T383335

This is only a proof of concept I wanted to share how we can use our self-signed CA certificates into a tool deployment by only using a volume mount from the k8s secret. This approach is super hacky as the file it mounts to usually contains all the certificates that live in /etc/ssl/certs. Normally you would add the cert under /usr/share/ca-certificates/ and run update-ca-certificates, but this would require us to either know the cert at image buildtime or to use something like an k8s operator or something to inject this later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant