scylladb / scylla-operator

The Kubernetes Operator for ScyllaDB
https://operator.docs.scylladb.com/
Apache License 2.0
327 stars 160 forks source link

Configure scylla-manager with CQL over TLS #1673

Open tnozicka opened 6 months ago

tnozicka commented 6 months ago

When manager talks to ScyllaClusters over CQL it should use TLS.

We need to look into how the manager can handle this as each ScyllaCluster has independent clientCA.

tnozicka commented 6 months ago

Looks like we could just create a per cluster manager client cert and sync them using https://github.com/scylladb/scylla-operator/blob/4be6fdbb1a6167a5e60e19d00ae6a4c2d5373cbe/pkg/mermaidclient/internal/models/cluster.go#L34-L40

scylla-operator-bot[bot] commented 3 weeks ago

The Scylla Operator project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

/lifecycle stale

rzetelskik commented 3 weeks ago

/remove-lifecycle stale /triage accepted