Skip to content

doc: certificate hot-reload for xDS gRPC connection#10628

Merged
mattklein123 merged 1 commit intoenvoyproxy:masterfrom
Nordix:path-based-sds-reload-docs
Apr 2, 2020
Merged

doc: certificate hot-reload for xDS gRPC connection#10628
mattklein123 merged 1 commit intoenvoyproxy:masterfrom
Nordix:path-based-sds-reload-docs

Conversation

@tsaarni
Copy link
Copy Markdown
Member

@tsaarni tsaarni commented Apr 2, 2020

Adds documentation for #10163.

Signed-off-by: Tero Saarni tero.saarni@est.tech

@repokitteh-read-only
Copy link
Copy Markdown

CC @envoyproxy/api-shepherds: Your approval is needed for changes made to api/.

🐱

Caused by: #10628 was opened by tsaarni.

see: more, trace.

@mattklein123 mattklein123 self-assigned this Apr 2, 2020
@tsaarni tsaarni force-pushed the path-based-sds-reload-docs branch 2 times, most recently from 9c2650f to 14525a3 Compare April 2, 2020 21:20
Copy link
Copy Markdown
Member

@mattklein123 mattklein123 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome, thank for the follow up. A few small comments. Thank you!

/wait

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should work for any SDS setup, right? Meaning this can be used for a standard TLS listener cert rotation and is not specific to xDS? This is a feature request that comes up a ton so can we a) make it clear that this is also supported, and maybe also b) mention this somewhere in https://www.envoyproxy.io/docs/envoy/latest/intro/arch_overview/security/ssl with maybe a link to the example you created?

Comment on lines 132 to 133
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I might move this into the path docs below? WDYT?

Adds documentation for envoyproxy#10163.

Signed-off-by: Tero Saarni <tero.saarni@est.tech>
@tsaarni tsaarni force-pushed the path-based-sds-reload-docs branch from 14525a3 to a5c483b Compare April 2, 2020 22:12
@mattklein123
Copy link
Copy Markdown
Member

@tsaarni friendly request to not ever force push. It makes reviews more difficult. Please only add commits and merge master (note that suggested changes breaks DCO if that is what happened to you, sorry!). Thank you!

Copy link
Copy Markdown
Member

@mattklein123 mattklein123 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!!

@repokitteh-read-only repokitteh-read-only bot removed the api label Apr 2, 2020
@mattklein123 mattklein123 merged commit f5d2cc6 into envoyproxy:master Apr 2, 2020
@tsaarni
Copy link
Copy Markdown
Member Author

tsaarni commented Apr 2, 2020

@mattklein123 Thanks for review & merge!

Sorry for using force push, I will not use it in future! Some projects have not squashed PR commits so I grown a bad habit using it for "clean" history.

BTW I've been too focused on my xDS use case to realize that there are other uses for for certificate rotation for static resources outside that 👍Thanks for pointing that out!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants