Open fvaleri opened 3 years ago
Does cert-manager support this feature?
OLM currently manages certs and generates self-signed certs for things like webhooks but we are interested in getting out of that altogether and delegating to a tool like cert-manager instead. This is on the near term roadmap.
@exdx it looks like it is supported: https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificatePrivateKey
My concern is about "near term roadmap" meaning ... any real ETA for that? Good to know that OLM is moving toward using cert-manager but I don't see it as a trivial task but maybe I could be wrong.
@exdx in the meantime, is it possible to add a flag to enable that conversion?
I think it's possible, we would definitely review a patch with that enabled.
We will triage this issue more in our Thursday issue triage call at 10 AM EST, if you wanted to discuss with the members of the OLM team. https://docs.google.com/document/d/1LMQ5QlEYgGBeSc75fhHh-VFJ8_B2j4ieBcagIa-QfwU/edit#heading=h.8ngolbigvi7q
Thanks @exdx, that would be great.
One option is to create another volume mount in every APIService/Webhook that OLM creates in the PKCS8 such that this change is backwards-compatible. Changing the cert to PKCS8 entirely may risk breaking some of the existing APIServices and other components.
@exdx yes it makes more sense.
When I try to deploy a bundle containing a a ValidatingAdmissionWebhook linked to a Quarkus application deployment, I get the following exception when loading the generated TLS key:
Now, the OLM generates the key in SEC1/PEM format instead of the PKCS8/PEM format, which is required by the JDK. If I get the key from the generated secret and convert it to PKCS8 format, then it works fine.
Instead, certificates generated by the Service CA Operator work fine.
These are the format delimiters that you can see when extracting the key from the secret.
Is there a way to generate the key in PKCS8 format? If not, can we add a flag to support it?