Currently, the following configuration leads to the HTTP client connecting without TLS:
apiVersion: opa.stackable.tech/v1alpha1
kind: OpaCluster
metadata:
name: test-opa
spec:
clusterConfig:
userInfo:
backend:
keycloak:
hostname: keycloak.example.com
clientCredentialsSecret: opa-infofetcher-keycloak-secret
adminRealm: master
userRealm: master
And to enable TLS, you have to jump through a few hoops by adding:
tls:
verification:
server:
caCert:
webPki: {}
In this day-in-age, I think it is expected to default to TLS (and the CRA requires secure-by-default).
So I propose that we impl Default for tls:
impl Default for TlsVerification {
fn default() -> Self {
Self::Server(TlsServerVerification {
ca_cert: CaCert::WebPki {},
})
}
}
... and explicit steps are to be taken to disable TLS or to ignore verification (or set internal PKI), eg:
or
tls:
verification:
none: {}
Currently, the following configuration leads to the HTTP client connecting without TLS:
And to enable TLS, you have to jump through a few hoops by adding:
In this day-in-age, I think it is expected to default to TLS (and the CRA requires secure-by-default).
So I propose that we
impl Defaultfortls:... and explicit steps are to be taken to disable TLS or to ignore verification (or set internal PKI), eg:
or