-
Notifications
You must be signed in to change notification settings - Fork 831
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: One side TLS for Kafka #4916
Merged
RafalSkolasinski
merged 15 commits into
SeldonIO:v2
from
RafalSkolasinski:one-side-tls-kafka
Jun 28, 2023
Merged
feat: One side TLS for Kafka #4916
RafalSkolasinski
merged 15 commits into
SeldonIO:v2
from
RafalSkolasinski:one-side-tls-kafka
Jun 28, 2023
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Closed
Previously this only happened if both were specified, indicating mTLS. This now allows for normal, one-sided TLS and default trust (trust via the built-in CA bundle). Add TLS provider method for retrieving just key store Remove TLS provider method for retrieving all stores Refactor Kafka SSL setup so client-provided auth is optional
For reference, strimzi listeners configuration for testing:
values for plain test:
values for one sided TLS test
values for mTLS test
values for confluent cloud kafka test
|
adriangonz
reviewed
Jun 21, 2023
scheduler/data-flow/src/main/kotlin/io/seldon/dataflow/kafka/Configuration.kt
Show resolved
Hide resolved
adriangonz
approved these changes
Jun 28, 2023
works as expected. Thank you very much! 💯 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Building on top of #4658
Closes #4870
Tested with:
To make use of one -sided TLS simply leave
security.kafka.ssl.client.secret
value unset, e.g.Note: this also adds propagation of
Helm value to Golang client if SSL or SASL_SSL is being used.
Empty value will result in
none
value being set as otherwise golang client raises