feature: letsencrypt http.Handler - #3535
Conversation
efbe6d7 to
e6b4ba5
Compare
e6b4ba5 to
9aa7e75
Compare
Deployment ChecklistThis change falls under the deployment policy. 💁 Since Nov 10th, we are in the RED deployment zone. This means all changes released to production must adhere to the following requirements:
👉 Regardless of which boxes you click in this comment, merge/deployment will not be blocked. |
9aa7e75 to
d3dd25d
Compare
1348d8f to
c1e6a3d
Compare
1d69abe to
be8f7a6
Compare
be8f7a6 to
630543f
Compare
8cb4f34 to
6240641
Compare
6240641 to
6d39cce
Compare
81c484d to
bbc32dd
Compare
|
|
||
| // TODO(sszuecs): does it make sense or do we want to chain TLSConfigs? | ||
| if o.Letsencrypt != nil { | ||
| return o.Letsencrypt.TLSConfig(), nil |
There was a problem hiding this comment.
@MustafaSaber @a4180p wdyt?
chain it or return here?
There was a problem hiding this comment.
Please check this function. I wrote a one letsencrypt test for it and did not change the tests that existed so we do not break anyone.
…rent storage/cache systems to be used by different deployments Signed-off-by: Sandor Szuecs <sandor.szuecs@zalando.de>
bbc32dd to
4bc8ad0
Compare
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
test: letsencrypt TLSConfig Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
…ipper proxies Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
a4180p
left a comment
There was a problem hiding this comment.
I think we should also add docs for the feature, but it could be done later.
| func (d *DirCache) Get(ctx context.Context, key string) ([]byte, error) { | ||
| val, err := d.cache.Get(ctx, key) | ||
| if err != nil { | ||
| logrus.Errorf("Get %q -> %v", key, err) |
There was a problem hiding this comment.
we must return autocert.ErrMissCache if cerificate is not found in cache or certificate will not be created in case of cache miss
https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.57.0:acme/autocert/autocert.go;l=304-314
There was a problem hiding this comment.
Interesting, but I think we do because we wrap here the autocert.DirCache and it will return this kind of error. So the error returned will be this.
https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.57.0:acme/autocert/cache.go;l=59
There was a problem hiding this comment.
fixed in the other implementations: RemoteCache and InmemoryCache
… on cache miss to do the handshake to get a new cert Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
|
👍 |
feature: letsencrypt http.Handler integration via autocert with different storage/cache systems to be used by different deployments
Test:
I am running this now since a while on my personal websites and completely replaced certbot+apache+cron to automate certs via skipper+curl+cron.
ref: closes #1786