internal: TLS P2 harden (fork CI only) - #6
Open
songzhendong wants to merge 3 commits into
Open
Conversation
Add SW_AGENT_FORCE_TLS and SSL CA/cert/key paths; share tls helpers across gRPC and HTTP; convert PKCS#1 keys to PKCS#8 for HTTP stacks that reject PKCS#1. Follow symlinks so Kubernetes secret mounts work. Never raise TLS misconfig into the host process: warn and degrade (plaintext / system trust / one-way TLS), including OSError from SSLContext load races and path expanduser/resolve failures. Validate CA and client PEMs when building material so bad content does not defer failure to connect time; FORCE_TLS fallback never attaches client certs, and credential build failure may warn and stay plaintext rather than abort start. Keep HTTP mTLS temp PEMs fork-safe via register_at_fork rebind. Drop test-only ssl_target_name_override; TLS peer-name follows grpc.default_authority. Generate e2e PEMs via shared gen-e2e-tls-certs.sh in digest-pinned alpine/openssl (no apk; PEMs not committed). mTLS e2e healthchecks the sharing-server port.
Extract PKCS#1 / CERTIFICATE PEM between BEGIN/END only so preamble and UTF-8 BOM cannot break b64decode or aio SSLContext cadata. Always verify HTTP with a process-lifetime CA temp snapshot (not the resolved K8s ..data path) so secret rotation cannot invalidate an open session.
When the HTTP CA snapshot cannot be written, fall back to the still-readable configured CA path instead of Requests' system trust store. Extract both CERTIFICATE and TRUSTED CERTIFICATE blocks (labels/trust attrs preserved) so openssl -trustout CAs remain usable for sync HTTPS; aio falls back to cafile when cadata rejects TRUSTED CERTIFICATE.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Note
Fork CI only — do not merge to apache. Official PR remains on
feat/grpc-http-tls-mtls.Test plan
unittest tests.unit.test_tls(33 ok, 2 skipped on Windows symlinks)