Uploaded image for project: 'OpenShift CFE'
  1. OpenShift CFE
  2. CFE-986

Openshift Router to watch defaultDestinationCA file and reload on updates to CA bundle.

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • openshift-4.17
    • openshift-4.15
    • None
    • None
    • CFE Sprint 245, CFE Sprint 246, CFE Sprint 247

      Openshift Router should create file watcher on `/var/run/configmaps/ca-trust/ca-bundle.crt` i.e. defaultDestinationCA and refresh haproxy.config and reload haproxy whenever the file is updated.

      Acceptance Criteria:

      • Whenever a service is created with the certificates signed by a new CA, and route for the same is created without destinationCA and`admin-ca-bundle` is updated with the new CA, the traffic to new service should go through seamlessly.(Expect some delay in the CA bundle to be updated by router).

            bhb@redhat.com Bharath B
            bhb@redhat.com Bharath B
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: