Skip to content

0.6.0

Choose a tag to compare

@voidrunner3074 voidrunner3074 released this 05 Jul 10:26
· 72 commits to master since this release
68d38e5

Added

  • Hot reload of TLS certificates. Aastro watches the directories of the configured cert_file,
    key_file, and ca_file paths and atomically swaps the in-memory material
    when they change. New TLS handshakes use the new certificate; in-flight
    connections are unaffected. No configuration change is required — rotation
    works on the existing cert paths.

    Directory-level watching handles both atomic file replacement on a host
    (write-to-temp-then-rename) and Kubernetes secret mounts, where the projected
    files are updated via symlink swap rather than in-place writes. Certificate
    rotation through cert-manager, Vault Agent, or SPIFFE/SPIRE sidecars is now
    hands-off.

    Reloads are validated before they are applied: if a new certificate or CA
    bundle on disk fails to parse, the error is logged and the previously loaded
    material stays live, so a malformed rotation cannot take the listener down.