Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support certificates reloading #5503

Closed
csuzhangxc opened this issue Jul 29, 2022 · 3 comments · Fixed by #6346 or #6527
Closed

Support certificates reloading #5503

csuzhangxc opened this issue Jul 29, 2022 · 3 comments · Fixed by #6346 or #6527
Labels
component/compute type/feature-request Categorizes issue or PR as related to a new feature.

Comments

@csuzhangxc
Copy link
Member

Feature Request

Is your feature request related to a problem? Please describe:

We use cert-manager to manage the TLS cert for the TiDB Cluster. When the cert expired, cert-manager renewed the cert, but TiFlash didn't reload the new cert online.

Describe the feature you'd like:

TiFlash reloads the TLS cert online, both for client connection and mTLS.

for TiKV, I found tikv/tikv#7150, but it seems still does not work well. for other components of TiDB, I haven't tested them yet.

Describe alternatives you've considered:

Teachability, Documentation, Adoption, Migration Strategy:

@csuzhangxc csuzhangxc added the type/feature-request Categorizes issue or PR as related to a new feature. label Jul 29, 2022
@csuzhangxc
Copy link
Member Author

TiKV fixed the issue in tikv/tikv#12569 and released it in v5.4.2, 6.1+

@JaySon-Huang
Copy link
Contributor

@ywqzzy Do we have a Grafana panel to show that certificate reload happens? Maybe we should add one.

@ywqzzy
Copy link
Contributor

ywqzzy commented Dec 22, 2022

@ywqzzy Do we have a Grafana panel to show that certificate reload happens? Maybe we should add one.

I have added one e2e test to make sure the reload process happens.
And I will add one grafana panel soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
component/compute type/feature-request Categorizes issue or PR as related to a new feature.
Projects
None yet
3 participants