This repository has been archived by the owner on Jan 8, 2024. It is now read-only.
Server automatically reloads TLS cert files on change #2346
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This makes it so that the Waypoint server will automatically rotate the TLS certificate when it detects a file change on disk. This happens with no disruption to any network connections.
This is particularly useful in a Kubernetes environment where the TLS certs may be coming from a mounted secret. When the secret changes, Kubernetes will update the files. In this scenario, the Waypoint server will begin using the new TLS certificate as soon as it can.
I brought in an
internal/pkg/cert
package that I've been copying around for years in various projects. 😛