Support certificate auto-rotation in Kestrel #32351
Description
Activity
This is a feature we're considering, above and beyond kubernetes. We're not at the design stage yet, but it's on the radar
@blowdart this is something I think we should support natively. We did work in .NET 5 to make Kestrel respect configuration reload but that doesn't work well for things in configuration that change without configuration itself changing.
This is going to affect YARP as well @Tratcher.
@aelij Are you using certmgr?
@davidfowl No, we're planning on using the new Secrets Store CSI Driver once it's out of preview, which natively supports auto-rotation.
Reacted by David Fowler@blowdart Removing this from 6. Please move it back if you think it should get done.
78 remaining items
There's little advantage to dropping the mtime check without also forcing polling since
FileSystemWatcherwon't resolve symlinks. I guess the chief advantage would be being able to respect the polling environment variables.While we're talking about runtime improvements, it would be nice if the non-polling watcher just didn't send duplicate events. 😉
it would be nice if the non-polling watcher just didn't send duplicate events. 😉
Regardless of which path we take, I'll need to update the code to stop instantiating
PhysicalFileWatcherdirectlyI made this change here. Unfortunately, I don't think we'll be able to take it for 8.0 because it will prevent us from using polling for specific files (the file watcher is shared by several consumers). Not having it is an abstraction violation, but fixing it doesn't fix the abstraction violation because we still pass the path directly to
X509Certificate, rather than retrieving a stream from the file provider.- added 2 commits that reference this issue
on Aug 22, 2023 PR for polling and ignoring mtime: #50251
It took a bit of massaging, but I got @aelij's repro script working (he was naively taking for granted that I would know when and how to log in to azure 😆). With #50251, I'm seeing
trce: Microsoft.AspNetCore.Server.Kestrel.Core.Internal.CertificatePathWatcher[15] Flagged 1 observers of '/certs/cert1.crt' as changed. ... info: Microsoft.AspNetCore.Server.Kestrel[0] Config changed. Stopping the following endpoints: 'https://*:5001' info: Microsoft.AspNetCore.Server.Kestrel[0] Config changed. Starting the following endpoints: 'https://*:5001'🥳
Reacted by Eli Arbel and pinkfloydx33I don't think there's "a usual". For example at my job by convention we put things into
/app/config,/app/secretsand/app/certs. But it could've been anywhere. I know some folks who just mount to/configwhile the program still runs from/app.IOW mounting k8s certs within the content root is certainly possible but is no way guaranteed. The mount point may be dictated by devops, and/or those responsible for managing configuration and might not even be a developer concern.
Reacted by Andrew Casey, Craig Treasure and Eli ArbelYes, there should be no relation to the app root.
It's in! @aelij I've already validated using your sample project (thanks again!), but it would be great if you could confirm that an upcoming nightly works for you.
Reacted by Craig TreasureNot sure why merging #50251 didn't close this...
I can confirm it's working. Thanks @amcasey!
Reacted by Andrew Casey and Craig Treasure- ghost locked as resolved and limited conversation to collaborators
on Sep 26, 2023
Is your feature request related to a problem? Please describe.
In Kubernetes, certificates are mounted as secret volumes, which can be configured to update automatically when the cert is rotated (e.g. from Key Vault). To achieve auto-rotation in Kestrel today, we need to hook up
ServerCertificateSelectorand listen to file changes (e.g. usingIFileProvider.Watch).Describe the solution you'd like
Add a
HttpsConnectionAdapterOptions.ServerCertificatePathproperty that would watch for file changes.