Skip to content

fix: preserve CA certificate references when sanitizing - #2262

Open
Shubham-Padkonde wants to merge 1 commit into
Kong:mainfrom
Shubham-Padkonde:fix/preserve-sanitized-ca-references
Open

Shubham-Padkonde wants to merge 1 commit into
Kong:mainfrom
Shubham-Padkonde:fix/preserve-sanitized-ca-references

Conversation

@Shubham-Padkonde

Copy link
Copy Markdown

Sanitizing a dump preserves CA certificate IDs but currently hashes references to those IDs in Services and plugin configuration. This leaves the sanitized configuration pointing at certificates that do not exist and can prevent it from being imported.

Preserve Service.CACertificates and plugin ca_certificates references, consistent with the existing CA certificate ID exemption. The regression exercises both reference locations and checks that unrelated service/plugin values and certificate contents are still sanitized.

Fixes #1830.

Validation:

  • The regression failed for both references before the fix.
  • Linux Go 1.26.6: go test -race -count=1 ./... passed.
  • Linux Go 1.27.1: go test -race -count=1 ./... passed.
  • Pinned golangci-lint v2.11.4 under Go 1.26.6: 0 issues.
  • git diff --check passed.

External Kong/Konnect integration tests requiring services or credentials were not run.

Prepared with Codex assistance.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

deck dump --sanitise not treating ca_certificate id embedded in other entities (like service) properly

2 participants