Skip to content

Conversation

@vihangm
Copy link
Member

@vihangm vihangm commented Jun 13, 2023

Summary: This switches to using the CA from the cluster certs
when monitoring vizier instead of skipping TLS Verify.

Type of change: /kind cleanup

Test Plan: skaffolded an operator and verified that it got the
CA and used it.

Changelog Message:

The Pixie Operator monitor now uses the Vizier CA in it's TLS Config
when making connections to NATS and CloudConn to check their status.

Signed-off-by: Vihang Mehta <vihang@pixielabs.ai>
@vihangm vihangm requested a review from a team June 13, 2023 21:21
@aimichelle aimichelle merged commit 5c3667e into pixie-io:main Jun 13, 2023
@vihangm vihangm deleted the tls_op branch June 13, 2023 22:00
aimichelle pushed a commit that referenced this pull request Jun 14, 2023
Summary: Using the pod advertised DNS addr instead of the IP address
ensures that the SSL cert is valid and that we can scrape with TLS.

Relevant Issues: Followup to a breakage caused by #1480

Type of change: /kind bug

Test Plan: skaffold the operator to test.

---------

Signed-off-by: Vihang Mehta <vihang@pixielabs.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants