Commit Graph
2002 Commits
Author SHA1 Message Date
jetstack-botandGitHub 7c53f88f19 Merge pull request #3476 from maelvls/unit-test-backoff-one-hour
Move the 'back off for 1 hour' logic to a unit-tested func
2020-12-08 11:02:17 +01:00
Maël Valais 62f8db6e6a refactor(issuing): PR review: use MustCreateCryptoBundle directly
Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-06 14:22:02 +01:00
Maël Valais 6484010f5c fix(issuing): wait until req matches cert before setting failure
The issuing controller wasn't checking if the certificate request that
it picked up is up to date. That resulted in the certificate being set
to "Failing" and "Issuing = False" due to an old certificate request
that was created during a previous issuance. The certificate would then
become stale.

Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-06 14:22:02 +01:00
Maël Valais 17cd05ecab test(issuing): new test: when req mismatches, cert can't be updated
This new unit test highlights an unexpected behavior of the issuing
controller: the issuing controller is updating the certificate's status
when the certificate request has a failure ("Reason = Failed"), but the
controller might have picked up an out-of-date certificate request.

The consequence is that the issuing controller would set the certificate
to "Issuing = False". That happens when a re-issuance is triggered with
an old failing certificate request.

Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-06 14:22:02 +01:00
Maël Valais 07fd8754f5 refactor(trigger): add test case when failure just happened
Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-06 13:51:12 +01:00
Maël Valais 769303c5f8 refactor(trigger): don't backoff when exactly 60min
As Maartje mentioned, it doesn't make sense to return backoff = true
while returning a delay of 0. Also, use time.UTC instead of time.Local.

Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-06 13:44:06 +01:00
Maël Valais 27d4924b5a refactor(trigger): move backoff logic to a unit-tested func
The trigger_controller_test.go has many unrelated test cases and I
thought it would be good to have more tightly scoped functions that are
easy to review (and most importantly, the unit tests are easy to
review).

Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-06 13:40:01 +01:00
jetstack-botandGitHub 0bcf759a25 Merge pull request #3433 from sorah/vault-issuer-exclude-root
Handle Vault issuer working as intermediate correctly
2020-12-03 09:23:14 +01:00
jetstack-botandGitHub fe84c50f7b Merge pull request #3485 from maelvls/bug-spurious-updates-aws
Strip X-Amzn-RequestId to avoid spurious challenge updates
2020-12-02 15:42:33 +01:00
Maël Valais 8d8dd02245 dns01-aws: aws-sdk-go already honors the proxy settings
No need for setting http.DefaultClient manually.

Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-01 13:26:29 +01:00
jetstack-botandGitHub 6fd14b0241 Merge pull request #3464 from wallrj/3396-renew-before-expiry-duration
Fix and deprecate the --renew-before-expiration-duration flag
2020-12-01 12:07:06 +01:00
Maël Valais 8a5748be94 dns01-aws: strip request id from aws errors
Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-12-01 11:11:05 +01:00
Maël Valais cccc0b1d4d dns01-aws: add test that reveals the request id issue
Signed-off-by: Maël Valais <mael.valais@gmail.com>
2020-11-30 13:31:12 +01:00
Sorah Fukumori f768afd0a3 vault: change condition precise
Signed-off-by: Sorah Fukumori <her@sorah.jp>
2020-11-28 18:13:49 +09:00
Sorah FukumoriandMaartje Eyskens 90c4f9e561 Avoid named return variables
Co-authored-by: Maartje Eyskens <maartje@eyskens.me>
Signed-off-by: Sorah Fukumori <her@sorah.jp>
2020-11-28 18:06:49 +09:00
jetstack-botandGitHub 7fbdd64876 Merge pull request #3347 from meyskens/acme-duration
Add duration into ACME
2020-11-24 10:37:01 +01:00
Maartje Eyskens a869c59cb7 Remove internal API tags and annotations
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 13:42:24 +01:00
jetstack-botandGitHub 92f4d7d349 Merge pull request #3384 from meyskens/no-acme-retry
Disable Go's ACME retry logic
2020-11-20 11:31:54 +00:00
Maartje Eyskens d705838e83 Implement feedback
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:46:49 +01:00
Maartje Eyskens 66f787ef33 Fix a lost EnableNotAfterDate
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:46:49 +01:00
Maartje Eyskens b7014c3dbd Fix rename in json too
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:46:49 +01:00
Maartje Eyskens 59048fed64 Rename field
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:46:49 +01:00
Maartje Eyskens 04d88479e4 Pass duration on until ACME order creation
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:46:49 +01:00
Maartje Eyskens 1b33e8029a Fix unit tests
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:46:08 +01:00
Maartje Eyskens 7b6573aa35 Add duration into ACME
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-20 09:45:32 +01:00
Richard Wall 1fc1fa88a0 Prevent instant renewal when the renewBefore value matches the duration
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
2020-11-19 15:00:27 +00:00
Richard Wall 95a229cc6e Unit tests for current behaviour
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
2020-11-19 13:01:00 +00:00
Richard Wall a33abd2060 Plumb through the flag provided defaultRenewBeforeExpiryDuration
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
2020-11-19 12:44:18 +00:00
Richard Wall 2b83331a2d Remove unused helper functions
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
2020-11-19 12:44:18 +00:00
Maartje Eyskens 61a7333955 Implement feedback
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-17 16:27:16 +01:00
4758efe7da Apply suggestions from code review
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>

Co-authored-by: Richard Wall <wallrj@users.noreply.github.com>
2020-11-17 16:03:58 +01:00
Maartje Eyskens 7c5cedf103 Update Bazel
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-10 10:35:11 +01:00
Maartje Eyskens b847c91054 Add boilerplate
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-10 10:32:31 +01:00
Mateusz Gozdek 27fa2f1ec4 Fix various typos found by codespell
Found by running this command:

codespell -S .git,*.png,go.sum -L keypair,iam,ans,unknwon,tage,ths,creater

Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com>
2020-11-07 14:55:13 +01:00
Maartje Eyskens f6e2d48a42 Add tests
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-11-06 17:16:56 +01:00
Sorah Fukumori 25fc672b80 vault: use issuing_ca field when no ca_chain available
Signed-off-by: Sorah Fukumori <her@sorah.jp>
2020-11-06 05:12:04 +09:00
Sorah Fukumori 69a0816ca1 vault: Handle missing ca_chain just in case
certutil should ensure CAChain always set...
https://github.com/hashicorp/vault/blob/3298836f6a90d95ff97af33cb2abd1f7269847df/sdk/helper/certutil/types.go

Signed-off-by: Sorah Fukumori <her@sorah.jp>
2020-11-06 05:12:03 +09:00
Sorah Fukumori 2f70e9d4db vault: extract PEM extraction to a dedicated function
Signed-off-by: Sorah Fukumori <her@sorah.jp>
2020-11-06 05:12:03 +09:00
Sorah FukumoriandChris Randles 64a5aecfdd Handle Vault issuer working as intermediate correctly
This patch changes a certificate issued with Vault issuer as follows:

- `ca.crt`: a root certificate, returned in `ca_chain` from Vault
- `tls.crt`: a leaf certificate, plus intermediate certificates
  if available in `ca_chain`

  i.e. `tls.crt` won't include a root certificate

This is a breaking change; Vault issuer had included an issuing CA as
a chain in `tls.crt`, but after this change it will no longer include a root
certificate when the issuing CA is not an intermediate. For `ca.crt`, it
had included a issuing CA only, which can be an intermediate.

`tls.crt` is not expected to contain a root certificate, as generally
clients must trust root certificates in advance. It is considered
redundant transmitting a root certificate from servers to clients during TLS
handshake. Other issuers, e.g. ACME, behave the same.

This fixes https://github.com/jetstack/cert-manager/issues/2166

This patch is based on https://github.com/jetstack/cert-manager/pull/3340

Co-authored-by: Chris Randles <randles.chris@gmail.com>
Signed-off-by: Sorah Fukumori <her@sorah.jp>
2020-11-06 05:12:03 +09:00
jetstack-botandGitHub 8127f0ad42 Merge pull request #3417 from meyskens/fix-gdns-log
Fix missing log in struct
2020-10-28 17:38:12 +00:00
jetstack-botandGitHub fda1c091e3 Merge pull request #3399 from meyskens/fix-panic-challenge
Fix a panic when changing the max concurrent challenges
2020-10-28 14:16:12 +00:00
Maartje Eyskens ed7b4cca60 Fix missing log in struct
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-10-28 15:08:37 +01:00
jetstack-botandGitHub 9654b533f4 Merge pull request #3409 from wallrj/api-validation-for-venafi-issuer-config
Add API validation for Venafi Issuer config
2020-10-28 09:52:12 +00:00
Richard Wall 885755630c Add API validation for Venafi Issuer config
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
2020-10-22 15:04:11 +01:00
Maartje Eyskens c0d88c28e4 Add a unit test for more challenges than previously allowed
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-10-22 14:45:02 +02:00
Maartje Eyskens 7d90fae6e4 Update bazel
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-10-21 19:47:27 +02:00
Lars Lehtonen 4d090fe0b7 pkg/issuer/acme/dns: replace deprecated AWS function
Signed-off-by: Lars Lehtonen <lars.lehtonen@gmail.com>
2020-10-21 09:49:47 -07:00
Maartje Eyskens 229425ad3a Use status code
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-10-21 17:03:19 +02:00
Maartje Eyskens 42803173cb Fix a panic when changing the max concurrent challenges
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
2020-10-20 15:45:45 +02:00
jetstack-botandGitHub 0754659260 Merge pull request #3376 from meyskens/document-issuer-set
Document a bit more about the IssuerConfig
2020-10-20 11:40:10 +02:00