Repository navigation
Router authn/z part 2.5: podcertcontroller: Don't load pod in podidentity signer - #2389
Open
Taahir Ahmed (ahmedtd) wants to merge 3 commits into
Open
Taahir Ahmed (ahmedtd) wants to merge 3 commits into
Taahir Ahmed (ahmedtd) wants to merge 3 commits into
Conversation
…router
Add --ingress-auth-mode=:{static-mtls|insecure}.
In static-mtls all clients must present a SPIFFE certificate (validated
with --ingress-client-ca-file). The SPIFFE ID is checked against an
allowlist (in --ingress-allowed-spiffe-ids).
In static-mtls mode, the router will refuse to start with a plaintext
listener.
Add --ingress-auth-mode to ate-setup, to pick between static-mtls and insecure modes for the ingress router. By default, static-mtls mode is set up to trust certificates issued by podidentity.podcert.ate.dev/identity, which is the most convenient option for setups running within the scope of a single cluster.
We should rely on the checks enforced by kube-apiserver. We don't need to double-check whether the pod exists. Upcoming e2e test changes will rely on the fact that non-Kubelet clients are allowed to create arbitary PodCertificateRequests, even if the pod or service account they reference does not exist.
Taahir Ahmed (ahmedtd)
requested review from
Eitan Yarmush (EItanya) and
Lior Lieberman (LiorLieberman)
October 9, 2026 04:18
Collaborator
|
Taahir Ahmed (@ahmedtd), is seems like the core function of this PR is actually the downstream mTLS changes to ingress. Can we update the description/purpose accordingly? Edit: I see this is stacked? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
We should rely on the checks enforced by kube-apiserver. We don't need to double-check whether the pod exists.
Upcoming e2e test changes will rely on the fact that non-Kubelet clients are allowed to create arbitary PodCertificateRequests, even if the pod or service account they reference does not exist. This will allow the test code running in Github Actions (or on the developer's machine) to authenticate to the router running within the cluster.