Uploaded image for project: 'Operator Runtime'
  1. Operator Runtime
  2. OPRUN-4110

Add CertPoolWatcher support to catalogd and catalogd CAs

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • 3
    • None
    • None
    • None

      CertPoolWatcher is currently only set up to support pull CAs in operator-controller. 

      It needs to be added to operator-controller for support of pull CAs. The HttpsClient uses a pool watcher to get its CAs, but nothing is watching the pool of pull secrets.

      Catalogd also needs a CertPoolWatcher for it's pull CAs.

      CertPoolWatcher also needs to restart the app when it determines that the SystemCertPool needs to be updated, as that pool cannot be updated once created. This is usually detected through changes to files referenced via SSL_CERT_FILE and SSL_CERT_DIR, as the SystemCertPool is referenced that way.

              tshort@redhat.com Todd Short
              tshort@redhat.com Todd Short
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: