Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking issue for TLS #75

Open
sed-i opened this issue Jun 21, 2023 · 0 comments
Open

Tracking issue for TLS #75

sed-i opened this issue Jun 21, 2023 · 0 comments

Comments

@sed-i
Copy link
Contributor

sed-i commented Jun 21, 2023

Enhancement Proposal

This is a tracking issue for end-to-end TLS in COS Lite.

Spec

TODO: Update

Steps / History

Traefik

Loki

Alertmanager

Prometheus

Prometheus – Alertmanager

Prometheus - grafana agent

  • TODO: Cert for remote-write

Grafana agent

Grafana

Catalogue

For the whole stack

To do later

Won't do

  • COS Config
  • COS Proxy

Unresolved Questions

  • With ingress per app, is it correct for all units of the same app have the same web_external_url in their certificate's SANs? I.e. would a CA complain if asked to generate two different certs for the same DNS? (The SANs of a unit's cert is made up of the unit's FQDN and the app's external url)
  • Should we also allow provisioning certificates with IPs as part of the SAN?
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant