Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-3296

Load all certificates in Kafka Exporter

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 2.0.0.GA
    • None
    • None
    • None
    • False
    • False

    Description

      During certificate renewals and replacement of private keys, the Cluster CA secret might contain more than one public key. The operands need to load all of them to be able to work during the rollouts when the other components might be using both the old and new certificate (they will always use only one of them, but e.g. one broker might already have the new while other has still the old).

      This currently does not happen and the Exporter uses only the ca.crt file. As a result, during Cluster CA key replacement, it will start crash-looping instead of rolling smoothly.

      Attachments

        Activity

          People

            Unassigned Unassigned
            scholzj JAkub Scholz
            Lukas Kral Lukas Kral
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: