Repository navigation
feat(tls): Configure TLS Curve Preferences for Redis HA Proxy - #1351
akhilnittala wants to merge 1 commit into
Conversation
Signed-off-by: akhil nittala <nakhil@redhat.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (7)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe central TLS profile now carries cluster curve preferences into Redis HAProxy configuration. Supported curve names are mapped to HAProxy names and rendered for bind and server connections when TLS is enabled. The default Redis HAProxy image and digest also change. ChangesRedis HAProxy TLS curve preferences
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant ClusterTLSProfile
participant Main as cmd/main.go
participant CentralProfile as CentralTLSConfigProfile
participant RedisConfig as GetRedisHAProxyConfig
participant CurveMapper as MapCurvePreferencesToHAProxyCurves
participant HaproxyTemplate as haproxy.cfg.tpl
ClusterTLSProfile->>Main: provides profile.Groups
Main->>CentralProfile: sets CurvePreferences
RedisConfig->>CurveMapper: maps CurvePreferences
CurveMapper-->>RedisConfig: returns supported HAProxy curve names
RedisConfig->>HaproxyTemplate: passes TLSCurves when nonempty
HaproxyTemplate-->>HaproxyTemplate: configures bind and server curves
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The Redis HAProxy curve configuration appears ready to merge after normal checks. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)✅ Passed checks (4 passed)Full details: Docstring CoverageExplanation Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 5 files. (2 skipped: 2 unsupported.)
Comment |
|
@akhilnittala: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
What does this PR do?
Configures TLS Curve Preferences for Redis HA Proxy. For PQC support we need to upgrade REDIS HA proxy image.
Fixes https://redhat.atlassian.net/browse/GITOPS-11599
PR acceptance criteria:
make serve-docsWhat type of PR is this?
/kind enhancement
Special notes to the reviewer: