Uploaded image for project: 'OpenShift Application Platform Engineering'
  1. OpenShift Application Platform Engineering
  2. OAPE-61

Openshift Router to watch defaultDestinationCA file and reload on updates to CA bundle.

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • None
    • None
    • Strategic Portfolio Work
    • 3
    • True
    • Show
      Blocked by https://issues.redhat.com/browse/NE-1479
    • False
    • Impediment
    • CFE Sprint 245, CFE Sprint 246, CFE Sprint 247
    • 3

      Openshift Router should create file watcher on `/var/run/configmaps/ca-trust/ca-bundle.crt` i.e. defaultDestinationCA and refresh haproxy.config and reload haproxy whenever the file is updated.

      Acceptance Criteria:

      • Whenever a service is created with the certificates signed by a new CA, and route for the same is created without destinationCA and`admin-ca-bundle` is updated with the new CA, the traffic to new service should go through seamlessly.(Expect some delay in the CA bundle to be updated by router).

            [OAPE-61] Openshift Router to watch defaultDestinationCA file and reload on updates to CA bundle.

            There are no comments yet on this issue.

              bhb@redhat.com Bharath B
              bhb@redhat.com Bharath B
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: