New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ocsp-updater: Split work by a configurable serial suffix shard #5628
ocsp-updater: Split work by a configurable serial suffix shard #5628
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One small nit.
Co-authored-by: Samantha <hello@entropy.cat>
A natural evolution for this would be a worker (goroutine) for each configured shards so that we don't have to check for full serial coverage (e.g. do each of these shards make a whole) at the configuration management layer (SaltStack). One drawback of this current implementation is that |
- Enable`ocsp-updater` to query for serials matching a configurable suffix to allow for multiple `ocsp-updater` instances at once - Add field `SerialSuffixShards` to `OCSPUpdaterConfig` - Add field `serialSuffixShards` to `test/config-next/ocsp-updater.json` - Add codepath to default to the previous query when `serialSuffixShards` is missing from the JSON config Part of #5629 Fixes #5625
ocsp-updater
to query for serials matching a configurable suffix toallow for multiple
ocsp-updater
instances at onceSerialSuffixShards
toOCSPUpdaterConfig
serialSuffixShards
totest/config-next/ocsp-updater.json
serialSuffixShards
ismissing from the JSON config
Part of #5629
Fixes #5625