CTFE Storage Saving: Extra Data Issuance Chain Deduplication
To reduce CT/Trillian database storage by deduplication of the entire issuance chain (intermediate certificate(s) and root certificate) that is currently stored in the Trillian merkle tree leaf ExtraData field. Storage cost should be reduced by at least 33% for new CT logs with this feature enabled. Currently only MySQL/MariaDB is supported to store the issuance chain in the CTFE database.
Existing logs are not affected by this change.
Log operators can choose to opt-in this change for new CT logs by adding new CTFE configs in the LogMultiConfig and importing the database schema. See example.
ctfe_storage_connection_string
extra_data_issuance_chain_storage_backend
An optional LRU cache can be enabled by providing the following flags.
cache_type
cache_size
cache_ttl
This change is tested in Cloud Build tests using the mysql:8.4 Docker image as of the time of writing.
CTFE Storage Saving: Extra Data Issuance Chain Deduplication
To reduce CT/Trillian database storage by deduplication of the entire issuance chain (intermediate certificate(s) and root certificate) that is currently stored in the Trillian merkle tree leaf ExtraData field. Storage cost should be reduced by at least 33% for new CT logs with this feature enabled. Currently only MySQL/MariaDB is supported to store the issuance chain in the CTFE database.
Existing logs are not affected by this change.
Log operators can choose to opt-in this change for new CT logs by adding new CTFE configs in the LogMultiConfig and importing the database schema. See example.
ctfe_storage_connection_string
extra_data_issuance_chain_storage_backend
An optional LRU cache can be enabled by providing the following flags.
cache_type
cache_size
cache_ttl
This change is tested in Cloud Build tests using the mysql:8.4 Docker image as of the time of writing.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps github.com/google/certificate-transparency-go from 1.1.8 to 1.2.1.
Release notes
Sourced from github.com/google/certificate-transparency-go's releases.
... (truncated)
Changelog
Sourced from github.com/google/certificate-transparency-go's changelog.
... (truncated)
Commits
2308f62
Update CHANGELOG.md for v1.2.1 release (#1497)d28d13e
Fix Go potential bugs and maintainability (#1496)1a675fd
Bump google.golang.org/grpc from 1.63.2 to 1.64.0 (#1482)0c9c98f
Update CHANGELOG.md for v1.2.0 release (#1495)998b8f6
Fix incorrect deployment doc and server config (#1494)414a850
Bump alpine from58d02b4
to77726ef
in /internal/witness/cmd/feeder (#1493)e329a8e
--- (#1491)a3fb01e
CTFE Extra Data Issuance Chain Deduplication (#1477)64bda79
--- (#1490)ae7c4db
Regenerate proto files (#1489)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show