jetstack-bot and GitHub
7c53f88f19
Merge pull request #3476 from maelvls/unit-test-backoff-one-hour
...
Move the 'back off for 1 hour' logic to a unit-tested func
2020-12-08 11:02:17 +01:00
Maël Valais
62f8db6e6a
refactor(issuing): PR review: use MustCreateCryptoBundle directly
...
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 14:22:02 +01:00
Maël Valais
6484010f5c
fix(issuing): wait until req matches cert before setting failure
...
The issuing controller wasn't checking if the certificate request that
it picked up is up to date. That resulted in the certificate being set
to "Failing" and "Issuing = False" due to an old certificate request
that was created during a previous issuance. The certificate would then
become stale.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 14:22:02 +01:00
Maël Valais
17cd05ecab
test(issuing): new test: when req mismatches, cert can't be updated
...
This new unit test highlights an unexpected behavior of the issuing
controller: the issuing controller is updating the certificate's status
when the certificate request has a failure ("Reason = Failed"), but the
controller might have picked up an out-of-date certificate request.
The consequence is that the issuing controller would set the certificate
to "Issuing = False". That happens when a re-issuance is triggered with
an old failing certificate request.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 14:22:02 +01:00
Maël Valais
07fd8754f5
refactor(trigger): add test case when failure just happened
...
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 13:51:12 +01:00
Maël Valais
769303c5f8
refactor(trigger): don't backoff when exactly 60min
...
As Maartje mentioned, it doesn't make sense to return backoff = true
while returning a delay of 0. Also, use time.UTC instead of time.Local.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 13:44:06 +01:00
Maël Valais
27d4924b5a
refactor(trigger): move backoff logic to a unit-tested func
...
The trigger_controller_test.go has many unrelated test cases and I
thought it would be good to have more tightly scoped functions that are
easy to review (and most importantly, the unit tests are easy to
review).
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 13:40:01 +01:00
jetstack-bot and GitHub
0bcf759a25
Merge pull request #3433 from sorah/vault-issuer-exclude-root
...
Handle Vault issuer working as intermediate correctly
2020-12-03 09:23:14 +01:00
jetstack-bot and GitHub
fe84c50f7b
Merge pull request #3485 from maelvls/bug-spurious-updates-aws
...
Strip X-Amzn-RequestId to avoid spurious challenge updates
2020-12-02 15:42:33 +01:00
Maël Valais
8d8dd02245
dns01-aws: aws-sdk-go already honors the proxy settings
...
No need for setting http.DefaultClient manually.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-01 13:26:29 +01:00
jetstack-bot and GitHub
6fd14b0241
Merge pull request #3464 from wallrj/3396-renew-before-expiry-duration
...
Fix and deprecate the --renew-before-expiration-duration flag
2020-12-01 12:07:06 +01:00
Maël Valais
8a5748be94
dns01-aws: strip request id from aws errors
...
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-01 11:11:05 +01:00
Maël Valais
cccc0b1d4d
dns01-aws: add test that reveals the request id issue
...
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-11-30 13:31:12 +01:00
Sorah Fukumori
f768afd0a3
vault: change condition precise
...
Signed-off-by: Sorah Fukumori <her@sorah.jp >
2020-11-28 18:13:49 +09:00
Sorah Fukumori and Maartje Eyskens
90c4f9e561
Avoid named return variables
...
Co-authored-by: Maartje Eyskens <maartje@eyskens.me >
Signed-off-by: Sorah Fukumori <her@sorah.jp >
2020-11-28 18:06:49 +09:00
jetstack-bot and GitHub
7fbdd64876
Merge pull request #3347 from meyskens/acme-duration
...
Add duration into ACME
2020-11-24 10:37:01 +01:00
Maartje Eyskens
a869c59cb7
Remove internal API tags and annotations
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 13:42:24 +01:00
jetstack-bot and GitHub
92f4d7d349
Merge pull request #3384 from meyskens/no-acme-retry
...
Disable Go's ACME retry logic
2020-11-20 11:31:54 +00:00
Maartje Eyskens
d705838e83
Implement feedback
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:46:49 +01:00
Maartje Eyskens
66f787ef33
Fix a lost EnableNotAfterDate
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:46:49 +01:00
Maartje Eyskens
b7014c3dbd
Fix rename in json too
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:46:49 +01:00
Maartje Eyskens
59048fed64
Rename field
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:46:49 +01:00
Maartje Eyskens
04d88479e4
Pass duration on until ACME order creation
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:46:49 +01:00
Maartje Eyskens
1b33e8029a
Fix unit tests
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:46:08 +01:00
Maartje Eyskens
7b6573aa35
Add duration into ACME
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-20 09:45:32 +01:00
Richard Wall
1fc1fa88a0
Prevent instant renewal when the renewBefore value matches the duration
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 15:00:27 +00:00
Richard Wall
95a229cc6e
Unit tests for current behaviour
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 13:01:00 +00:00
Richard Wall
a33abd2060
Plumb through the flag provided defaultRenewBeforeExpiryDuration
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 12:44:18 +00:00
Richard Wall
2b83331a2d
Remove unused helper functions
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 12:44:18 +00:00
Maartje Eyskens
61a7333955
Implement feedback
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-17 16:27:16 +01:00
4758efe7da
Apply suggestions from code review
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
Co-authored-by: Richard Wall <wallrj@users.noreply.github.com >
2020-11-17 16:03:58 +01:00
Maartje Eyskens
7c5cedf103
Update Bazel
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-10 10:35:11 +01:00
Maartje Eyskens
b847c91054
Add boilerplate
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-10 10:32:31 +01:00
Mateusz Gozdek
27fa2f1ec4
Fix various typos found by codespell
...
Found by running this command:
codespell -S .git,*.png,go.sum -L keypair,iam,ans,unknwon,tage,ths,creater
Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com >
2020-11-07 14:55:13 +01:00
Maartje Eyskens
f6e2d48a42
Add tests
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-11-06 17:16:56 +01:00
Sorah Fukumori
25fc672b80
vault: use issuing_ca field when no ca_chain available
...
Signed-off-by: Sorah Fukumori <her@sorah.jp >
2020-11-06 05:12:04 +09:00
Sorah Fukumori
69a0816ca1
vault: Handle missing ca_chain just in case
...
certutil should ensure CAChain always set...
https://github.com/hashicorp/vault/blob/3298836f6a90d95ff97af33cb2abd1f7269847df/sdk/helper/certutil/types.go
Signed-off-by: Sorah Fukumori <her@sorah.jp >
2020-11-06 05:12:03 +09:00
Sorah Fukumori
2f70e9d4db
vault: extract PEM extraction to a dedicated function
...
Signed-off-by: Sorah Fukumori <her@sorah.jp >
2020-11-06 05:12:03 +09:00
Sorah Fukumori and Chris Randles
64a5aecfdd
Handle Vault issuer working as intermediate correctly
...
This patch changes a certificate issued with Vault issuer as follows:
- `ca.crt`: a root certificate, returned in `ca_chain` from Vault
- `tls.crt`: a leaf certificate, plus intermediate certificates
if available in `ca_chain`
i.e. `tls.crt` won't include a root certificate
This is a breaking change; Vault issuer had included an issuing CA as
a chain in `tls.crt`, but after this change it will no longer include a root
certificate when the issuing CA is not an intermediate. For `ca.crt`, it
had included a issuing CA only, which can be an intermediate.
`tls.crt` is not expected to contain a root certificate, as generally
clients must trust root certificates in advance. It is considered
redundant transmitting a root certificate from servers to clients during TLS
handshake. Other issuers, e.g. ACME, behave the same.
This fixes https://github.com/jetstack/cert-manager/issues/2166
This patch is based on https://github.com/jetstack/cert-manager/pull/3340
Co-authored-by: Chris Randles <randles.chris@gmail.com >
Signed-off-by: Sorah Fukumori <her@sorah.jp >
2020-11-06 05:12:03 +09:00
jetstack-bot and GitHub
8127f0ad42
Merge pull request #3417 from meyskens/fix-gdns-log
...
Fix missing log in struct
2020-10-28 17:38:12 +00:00
jetstack-bot and GitHub
fda1c091e3
Merge pull request #3399 from meyskens/fix-panic-challenge
...
Fix a panic when changing the max concurrent challenges
2020-10-28 14:16:12 +00:00
Maartje Eyskens
ed7b4cca60
Fix missing log in struct
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-10-28 15:08:37 +01:00
jetstack-bot and GitHub
9654b533f4
Merge pull request #3409 from wallrj/api-validation-for-venafi-issuer-config
...
Add API validation for Venafi Issuer config
2020-10-28 09:52:12 +00:00
Richard Wall
885755630c
Add API validation for Venafi Issuer config
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-10-22 15:04:11 +01:00
Maartje Eyskens
c0d88c28e4
Add a unit test for more challenges than previously allowed
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-10-22 14:45:02 +02:00
Maartje Eyskens
7d90fae6e4
Update bazel
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-10-21 19:47:27 +02:00
Lars Lehtonen
4d090fe0b7
pkg/issuer/acme/dns: replace deprecated AWS function
...
Signed-off-by: Lars Lehtonen <lars.lehtonen@gmail.com >
2020-10-21 09:49:47 -07:00
Maartje Eyskens
229425ad3a
Use status code
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-10-21 17:03:19 +02:00
Maartje Eyskens
42803173cb
Fix a panic when changing the max concurrent challenges
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-10-20 15:45:45 +02:00
jetstack-bot and GitHub
0754659260
Merge pull request #3376 from meyskens/document-issuer-set
...
Document a bit more about the IssuerConfig
2020-10-20 11:40:10 +02:00