K8SPG-951: add spec.issuerConf#1684
Conversation
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
There was a problem hiding this comment.
Pull request overview
Adds spec.tls.issuerConf to the PostgresCluster API to support multiple cert-manager issuer modes (managed namespaced Issuer, managed cluster-scoped ClusterIssuer, and external/third-party issuers), and updates reconciliation logic so leaf certificates can reference the resolved issuerRef. The PR also adjusts controller-runtime client caching to allow direct API-server Get on ClusterIssuers without requiring cluster-wide list/watch RBAC, and adds tests covering the new behaviors.
Changes:
- Introduce
spec.tls.issuerConf(CRD + Go types + deepcopy) to configure issuer references. - Implement issuer-mode resolution and apply logic for Issuer/ClusterIssuer/external issuers, plus CA handling fallbacks for external issuers.
- Disable controller-runtime cache for
cert-manager.io/v1 ClusterIssuerand add/extend unit tests.
Reviewed changes
Copilot reviewed 19 out of 21 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| pkg/apis/upstream.pgv2.percona.com/v1beta1/zz_generated.deepcopy.go | Deepcopy updates for the new TLSSpec.IssuerConf field. |
| pkg/apis/upstream.pgv2.percona.com/v1beta1/postgrescluster_types.go | Adds TLSSpec.IssuerConf to the API type. |
| percona/runtime/runtime.go | Disables informer cache for ClusterIssuer via ClientCacheOptions() and applies it to managers. |
| percona/runtime/runtime_test.go | Adds tests around cache options / manager creation. |
| percona/certmanager/certmanager.go | Implements issuer modes, issuerRef resolution, and managed/external behaviors across Apply* methods. |
| percona/certmanager/certmanager_test.go | Adds/extends tests for issuer modes, namespace resolution, drift updates, and external issuer behavior. |
| internal/naming/names.go | Adds naming helpers for cluster-scoped CA issuer/secret. |
| internal/naming/names_test.go | Tests for the new naming helpers. |
| internal/controller/postgrescluster/pki.go | Makes PKI reconciliation issuer-mode aware, including managed-cluster secret locations and external mode handling. |
| internal/controller/postgrescluster/pki_test.go | Adds issuer-mode awareness tests (with envtest/fake-client workarounds). |
| internal/controller/postgrescluster/pgbackrest.go | Adds CA selection helper for pgBackRest when using external issuers (no operator root CA). |
| internal/controller/postgrescluster/pgbackrest_test.go | Unit tests for pgBackRestCACert. |
| internal/controller/postgrescluster/instance.go | Adds CA selection helper for instance cert embedding when using external issuers. |
| internal/controller/postgrescluster/instance_test.go | Unit tests for instanceCACert. |
| internal/controller/postgrescluster/controller.go | Ensures cert-manager watch registration logic runs even when rootCA is nil (external mode). |
| deploy/cw-bundle.yaml | CRD schema update for spec.tls.issuerConf. |
| deploy/crd.yaml | CRD schema update for spec.tls.issuerConf. |
| deploy/bundle.yaml | CRD schema update for spec.tls.issuerConf. |
| config/crd/bases/upstream.pgv2.percona.com_postgresclusters.yaml | Base CRD schema update for spec.tls.issuerConf. |
| config/crd/bases/pgv2.percona.com_perconapgclusters.yaml | Base CRD schema update for spec.tls.issuerConf. |
| build/crd/percona/generated/pgv2.percona.com_perconapgclusters.yaml | Generated CRD schema update for spec.tls.issuerConf. |
Files not reviewed (1)
- pkg/apis/upstream.pgv2.percona.com/v1beta1/zz_generated.deepcopy.go: Generated file
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
| if err == nil { | ||
| needsUpdate := false | ||
|
|
||
| hasOwnerRef, err := controllerutil.HasOwnerReference(existing.OwnerReferences, cluster, c.scheme) | ||
| if err != nil { | ||
| return errors.Wrap(err, "check owner reference") | ||
| } | ||
|
|
||
| if !hasOwnerRef { | ||
| gvk := v1beta1.SchemeBuilder.GroupVersion.WithKind("PostgresCluster") | ||
| existing.OwnerReferences = []metav1.OwnerReference{{ | ||
| APIVersion: gvk.GroupVersion().String(), | ||
| Kind: gvk.Kind, | ||
| Name: cluster.GetName(), | ||
| UID: cluster.GetUID(), | ||
| BlockOwnerDeletion: ptr.To(true), | ||
| Controller: ptr.To(true), | ||
| }} | ||
| needsUpdate = true | ||
| if !clusterScoped { | ||
| hasOwnerRef, err := controllerutil.HasOwnerReference(existing.OwnerReferences, cluster, c.scheme) |
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
| if rootCA != nil { | ||
| caCert, err := rootCA.Certificate.MarshalText() | ||
| return caCert, errors.Wrap(err, "failed to marshal root CA certificate") | ||
| } | ||
|
|
||
| if ca := clientSecret.Data[corev1.ServiceAccountRootCAKey]; len(ca) > 0 { | ||
| return ca, nil | ||
| } | ||
| if ca := repoSecret.Data[corev1.ServiceAccountRootCAKey]; len(ca) > 0 { | ||
| return ca, nil | ||
| } | ||
|
|
||
| return nil, errors.New("external issuer did not return a CA certificate for pgBackRest") |
There was a problem hiding this comment.
why do we need these kind of fallbacks here and in instance.go? i'd expect rootCA to be passed properly by the CA issued by ClusterIssuer
There was a problem hiding this comment.
rootCA can be nil in case of external issuers or ClusterIssuer that are not managed by the operator (missing RBAC, created externally).. So in this case we just try to look at the issued leaf cert and get the ca.crt from there
commit: 8ce02eb |
CHANGE DESCRIPTION
Problem:
Adds support for specifying cert-manager issuer conf:
CHECKLIST
Jira
Needs Doc) and QA (Needs QA)?Tests
Config/Logging/Testability