fix(helm): derive metrics Certificate dnsNames from resourceName helper - #291
Open
kazuki-ma wants to merge 1 commit into
Open
fix(helm): derive metrics Certificate dnsNames from resourceName helper#291kazuki-ma wants to merge 1 commit into
kazuki-ma wants to merge 1 commit into
Conversation
The metrics Certificate hardcoded its dnsNames as clickhouse-operator-metrics-service while the metrics Service and the ServiceMonitor's tlsConfig.serverName are rendered through the clickhouse-operator.resourceName helper. With any release name other than the default fullname the SAN never matched and secure scraping failed x509 verification. Fixes ClickHouse#290 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The metrics Certificate hardcoded its dnsNames as
clickhouse-operator-metrics-servicewhile the metrics Service and the ServiceMonitor'stlsConfig.serverNameare rendered through theclickhouse-operator.resourceNamehelper. With any release name other than the default fullname the SAN never matched and secure scraping failed x509 verification (insecureSkipVerify: falsewhen certManager is enabled).What
Replaced the two hardcoded dnsNames entries in
dist/chart/templates/cert-manager/metrics-certs.yamlwith the sameclickhouse-operator.resourceNamehelper (suffixmetrics-service) that the metrics Service and the ServiceMonitor already use, so the certificate SANs always follow the rendered Service name.Verified with
helm template myrelease ./dist/chart --namespace demo --set prometheus.enabled=true --set certManager.enabled=true --set metrics.enabled=true --set metrics.secure=true: the Certificate dnsNames and the ServiceMonitor serverName now both rendermyrelease-clickhouse-operator-metrics-service.demo.svc.Related Issues
Fixes #290