-
Notifications
You must be signed in to change notification settings - Fork 38
/
certmanager_tls_config.go
69 lines (60 loc) · 1.9 KB
/
certmanager_tls_config.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
package certmanagerpki
import (
"context"
"crypto/tls"
"crypto/x509"
"sigs.k8s.io/controller-runtime/pkg/client"
"strings"
"github.com/konpyutaika/nifikop/api/v1alpha1"
"github.com/konpyutaika/nifikop/pkg/errorfactory"
corev1 "k8s.io/api/core/v1"
apierrors "k8s.io/apimachinery/pkg/api/errors"
"k8s.io/apimachinery/pkg/types"
)
// GetControllerTLSConfig creates a TLS config from the user secret created for
// cruise control and manager operations
func (c *certManager) GetControllerTLSConfig() (config *tls.Config, err error) {
config, err = GetControllerTLSConfigFromSecret(c.client, v1alpha1.SecretReference{
Namespace: c.cluster.Namespace,
Name: c.cluster.GetNifiControllerUserIdentity(),
})
return
}
func GetControllerTLSConfigFromSecret(client client.Client, ref v1alpha1.SecretReference) (config *tls.Config, err error) {
config = &tls.Config{}
tlsKeys := &corev1.Secret{}
err = client.Get(context.TODO(),
types.NamespacedName{
Namespace: ref.Namespace,
Name: ref.Name,
},
tlsKeys,
)
if err != nil {
if apierrors.IsNotFound(err) {
err = errorfactory.New(errorfactory.ResourceNotReady{}, err, "controller secret not found")
}
return
}
clientCert := tlsKeys.Data[corev1.TLSCertKey]
clientKey := tlsKeys.Data[corev1.TLSPrivateKeyKey]
caCert := tlsKeys.Data[v1alpha1.CoreCACertKey]
if len(caCert) == 0 {
certs := strings.SplitAfter(string(clientCert), "-----END CERTIFICATE-----")
clientCert = []byte(certs[0])
caCert = []byte(certs[len(certs)-1])
if len(certs) == 3 {
caCert = []byte(certs[len(certs)-2])
}
}
x509ClientCert, err := tls.X509KeyPair(clientCert, clientKey)
if err != nil {
err = errorfactory.New(errorfactory.InternalError{}, err, "could not decode controller certificate")
return
}
rootCAs := x509.NewCertPool()
rootCAs.AppendCertsFromPEM(caCert)
config.Certificates = []tls.Certificate{x509ClientCert}
config.RootCAs = rootCAs
return
}