Skip to content

K8SPG-951: add spec.issuerConf#1684

Open
mayankshah1607 wants to merge 21 commits into
mainfrom
K8SPG-951-issuer-conf
Open

K8SPG-951: add spec.issuerConf#1684
mayankshah1607 wants to merge 21 commits into
mainfrom
K8SPG-951-issuer-conf

Conversation

@mayankshah1607

@mayankshah1607 mayankshah1607 commented Jul 14, 2026

Copy link
Copy Markdown
Member

CHANGE DESCRIPTION

Problem:

Adds support for specifying cert-manager issuer conf:

apiVersion: pgv2.percona.com/v2
kind: PerconaPGCluster
metadata:
  name: cluster1
spec:
  tls:
    issuerConf:
      name: some-selfsigned-issuer
      kind: ClusterIssuer
      group: cert-manager.io

CHECKLIST

Jira

  • Is the Jira ticket created and referenced properly?
  • Does the Jira ticket have the proper statuses for documentation (Needs Doc) and QA (Needs QA)?
  • Does the Jira ticket link to the proper milestone (Fix Version field)?

Tests

  • Is an E2E test/test case added for the new feature/change?
  • Are unit tests added where appropriate?

Config/Logging/Testability

  • Are all needed new/changed options added to default YAML files?
  • Are all needed new/changed options added to the Helm Chart?
  • Did we add proper logging messages for operator actions?
  • Did we ensure compatibility with the previous version or cluster upgrade process?
  • Does the change support oldest and newest supported PG version?
  • Does the change support oldest and newest supported Kubernetes version?

Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds spec.tls.issuerConf to the PostgresCluster API to support multiple cert-manager issuer modes (managed namespaced Issuer, managed cluster-scoped ClusterIssuer, and external/third-party issuers), and updates reconciliation logic so leaf certificates can reference the resolved issuerRef. The PR also adjusts controller-runtime client caching to allow direct API-server Get on ClusterIssuers without requiring cluster-wide list/watch RBAC, and adds tests covering the new behaviors.

Changes:

  • Introduce spec.tls.issuerConf (CRD + Go types + deepcopy) to configure issuer references.
  • Implement issuer-mode resolution and apply logic for Issuer/ClusterIssuer/external issuers, plus CA handling fallbacks for external issuers.
  • Disable controller-runtime cache for cert-manager.io/v1 ClusterIssuer and add/extend unit tests.

Reviewed changes

Copilot reviewed 19 out of 21 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
pkg/apis/upstream.pgv2.percona.com/v1beta1/zz_generated.deepcopy.go Deepcopy updates for the new TLSSpec.IssuerConf field.
pkg/apis/upstream.pgv2.percona.com/v1beta1/postgrescluster_types.go Adds TLSSpec.IssuerConf to the API type.
percona/runtime/runtime.go Disables informer cache for ClusterIssuer via ClientCacheOptions() and applies it to managers.
percona/runtime/runtime_test.go Adds tests around cache options / manager creation.
percona/certmanager/certmanager.go Implements issuer modes, issuerRef resolution, and managed/external behaviors across Apply* methods.
percona/certmanager/certmanager_test.go Adds/extends tests for issuer modes, namespace resolution, drift updates, and external issuer behavior.
internal/naming/names.go Adds naming helpers for cluster-scoped CA issuer/secret.
internal/naming/names_test.go Tests for the new naming helpers.
internal/controller/postgrescluster/pki.go Makes PKI reconciliation issuer-mode aware, including managed-cluster secret locations and external mode handling.
internal/controller/postgrescluster/pki_test.go Adds issuer-mode awareness tests (with envtest/fake-client workarounds).
internal/controller/postgrescluster/pgbackrest.go Adds CA selection helper for pgBackRest when using external issuers (no operator root CA).
internal/controller/postgrescluster/pgbackrest_test.go Unit tests for pgBackRestCACert.
internal/controller/postgrescluster/instance.go Adds CA selection helper for instance cert embedding when using external issuers.
internal/controller/postgrescluster/instance_test.go Unit tests for instanceCACert.
internal/controller/postgrescluster/controller.go Ensures cert-manager watch registration logic runs even when rootCA is nil (external mode).
deploy/cw-bundle.yaml CRD schema update for spec.tls.issuerConf.
deploy/crd.yaml CRD schema update for spec.tls.issuerConf.
deploy/bundle.yaml CRD schema update for spec.tls.issuerConf.
config/crd/bases/upstream.pgv2.percona.com_postgresclusters.yaml Base CRD schema update for spec.tls.issuerConf.
config/crd/bases/pgv2.percona.com_perconapgclusters.yaml Base CRD schema update for spec.tls.issuerConf.
build/crd/percona/generated/pgv2.percona.com_perconapgclusters.yaml Generated CRD schema update for spec.tls.issuerConf.
Files not reviewed (1)
  • pkg/apis/upstream.pgv2.percona.com/v1beta1/zz_generated.deepcopy.go: Generated file

Comment thread percona/certmanager/certmanager.go
Comment thread percona/certmanager/certmanager.go
Comment thread percona/certmanager/certmanager.go Outdated
Comment thread percona/certmanager/certmanager.go Outdated
Comment thread percona/runtime/runtime_test.go Outdated
Comment thread pkg/apis/upstream.pgv2.percona.com/v1beta1/postgrescluster_types.go
mayankshah1607 and others added 11 commits July 15, 2026 12:40
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 26 out of 28 changed files in this pull request and generated 3 comments.

Files not reviewed (1)
  • pkg/apis/upstream.pgv2.percona.com/v1beta1/zz_generated.deepcopy.go: Generated file

Comment thread internal/naming/names.go
Comment thread internal/controller/postgrescluster/pki.go
Comment on lines 413 to +417
if err == nil {
needsUpdate := false

hasOwnerRef, err := controllerutil.HasOwnerReference(existing.OwnerReferences, cluster, c.scheme)
if err != nil {
return errors.Wrap(err, "check owner reference")
}

if !hasOwnerRef {
gvk := v1beta1.SchemeBuilder.GroupVersion.WithKind("PostgresCluster")
existing.OwnerReferences = []metav1.OwnerReference{{
APIVersion: gvk.GroupVersion().String(),
Kind: gvk.Kind,
Name: cluster.GetName(),
UID: cluster.GetUID(),
BlockOwnerDeletion: ptr.To(true),
Controller: ptr.To(true),
}}
needsUpdate = true
if !clusterScoped {
hasOwnerRef, err := controllerutil.HasOwnerReference(existing.OwnerReferences, cluster, c.scheme)
mayankshah1607 and others added 7 commits July 15, 2026 16:06
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
Signed-off-by: Mayank Shah <mayank.shah@percona.com>
@mayankshah1607
mayankshah1607 marked this pull request as ready for review July 17, 2026 14:19
@mayankshah1607 mayankshah1607 changed the title K8SPG-951: [WIP] add spec.issuerConf K8SPG-951: add spec.issuerConf Jul 20, 2026
Comment on lines +2339 to +2351
if rootCA != nil {
caCert, err := rootCA.Certificate.MarshalText()
return caCert, errors.Wrap(err, "failed to marshal root CA certificate")
}

if ca := clientSecret.Data[corev1.ServiceAccountRootCAKey]; len(ca) > 0 {
return ca, nil
}
if ca := repoSecret.Data[corev1.ServiceAccountRootCAKey]; len(ca) > 0 {
return ca, nil
}

return nil, errors.New("external issuer did not return a CA certificate for pgBackRest")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why do we need these kind of fallbacks here and in instance.go? i'd expect rootCA to be passed properly by the CA issued by ClusterIssuer

@mayankshah1607 mayankshah1607 Jul 20, 2026

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rootCA can be nil in case of external issuers or ClusterIssuer that are not managed by the operator (missing RBAC, created externally).. So in this case we just try to look at the issued leaf cert and get the ca.crt from there

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wouldn't it be better to stop reconciliation on a upper level if rootCA is nil rather than this fallback logic?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we return early, how would we know the root CA then? This fallback exists so that the root CA can be inferred from the externally issued leaf certs. Am I missing something?

@JNKPercona

Copy link
Copy Markdown
Collaborator
Test Name Result Time
backup-enable-disable passed 00:00:00
builtin-extensions passed 00:00:00
cert-manager-tls passed 00:00:00
custom-envs passed 00:00:00
custom-tls passed 00:00:00
database-init-sql passed 00:00:00
demand-backup passed 00:00:00
demand-backup-offline-snapshot passed 00:00:00
dynamic-configuration passed 00:00:00
finalizers passed 00:00:00
init-deploy passed 00:00:00
huge-pages passed 00:00:00
major-upgrade-14-to-15 passed 00:00:00
major-upgrade-15-to-16 passed 00:00:00
major-upgrade-16-to-17 passed 00:00:00
major-upgrade-17-to-18 passed 00:00:00
ldap passed 00:00:00
ldap-tls passed 00:00:00
monitoring passed 00:00:00
monitoring-pmm3 passed 00:00:00
one-pod passed 00:00:00
operator-self-healing passed 00:00:00
pgbouncer-mtls passed 00:00:00
pitr passed 00:00:00
scaling passed 00:00:00
scheduled-backup passed 00:00:00
self-healing passed 00:00:00
sidecars passed 00:00:00
standby-pgbackrest passed 00:00:00
standby-streaming passed 00:13:26
start-from-backup passed 00:00:00
tablespaces passed 00:00:00
telemetry-transfer passed 00:00:00
upgrade-consistency passed 00:00:00
upgrade-minor passed 00:00:00
users passed 00:00:00
migration-from-crunchy-standby passed 00:00:00
migration-from-crunchy-pv passed 00:00:00
migration-from-crunchy-backup-restore passed 00:00:00
Summary Value
Tests Run 39/39
Job Duration 00:27:49
Total Test Time 00:13:26

commit: 8ce02eb
image: perconalab/percona-postgresql-operator:PR-1684-8ce02ebb9

@mayankshah1607
mayankshah1607 requested a review from egegunes July 20, 2026 07:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants