Skip to content

User Info Fetcher: Enable TLS with WebPKI trust by default #517

Description

@NickLarsenNZ

Currently, the following configuration leads to the HTTP client connecting without TLS:

apiVersion: opa.stackable.tech/v1alpha1
kind: OpaCluster
metadata:
  name: test-opa
spec:
  clusterConfig:
    userInfo:
      backend:
        keycloak:
          hostname: keycloak.example.com
          clientCredentialsSecret: opa-infofetcher-keycloak-secret
          adminRealm: master
          userRealm: master

And to enable TLS, you have to jump through a few hoops by adding:

          tls:
            verification:
              server:
                caCert:
                  webPki: {}

In this day-in-age, I think it is expected to default to TLS (and the CRA requires secure-by-default).

So I propose that we impl Default for tls:

impl Default for TlsVerification {
    fn default() -> Self {
        Self::Server(TlsServerVerification {
            ca_cert: CaCert::WebPki {},
        })
    }
}

... and explicit steps are to be taken to disable TLS or to ignore verification (or set internal PKI), eg:

          tls: null 

or

          tls:
            verification:
              none: {}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions