Skip to content

feat(tls): Configure TLS Curve Preferences for Redis HA Proxy - #1351

Open
akhilnittala wants to merge 1 commit into
redhat-developer:masterfrom
akhilnittala:usr/akhil/configure_curve_preferences_HA_proxy
Open

akhilnittala wants to merge 1 commit into
redhat-developer:masterfrom
akhilnittala:usr/akhil/configure_curve_preferences_HA_proxy

Conversation

@akhilnittala

@akhilnittala akhilnittala commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

What does this PR do?

Configures TLS Curve Preferences for Redis HA Proxy. For PQC support we need to upgrade REDIS HA proxy image.
Fixes https://redhat.atlassian.net/browse/GITOPS-11599
PR acceptance criteria:

  • Documentation was updated and verified using make serve-docs
  • Unit tests were updated
  • E2E tests were updated

What type of PR is this?

/kind enhancement

Special notes to the reviewer:

  • deploy gitops operator on openshift cluster
  • test the curve settins by updating the TLS Central profile.

Signed-off-by: akhil nittala <nakhil@redhat.com>
@openshift-ci openshift-ci Bot added the kind/enhancement New feature or request label Oct 9, 2026
@openshift-ci

openshift-ci Bot commented Oct 9, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign chengfang for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9640b0b1-9b31-492a-a813-0db136784a18

📥 Commits

Reviewing files that changed from the base of the PR and between 311bf78 and d25d8c6.


📒 Files selected for processing (7)
  • argocd-operator/build/redis/haproxy.cfg.tpl
  • argocd-operator/common/defaults.go
  • argocd-operator/controllers/argoutil/redis.go
  • argocd-operator/controllers/argoutil/redis_test.go
  • argocd-operator/pkg/tlsprofile/profile.go
  • build/redis/haproxy.cfg.tpl
  • cmd/main.go

🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.



📝 Summary

Summary by CodeRabbit

  • New Features
    • Redis HAProxy now honors configured TLS curve preferences, including supported post-quantum hybrid groups, for both incoming and outgoing TLS connections.
    • Updated the default Redis HAProxy image to a newer build with support for post-quantum TLS groups.

Walkthrough

The central TLS profile now carries cluster curve preferences into Redis HAProxy configuration. Supported curve names are mapped to HAProxy names and rendered for bind and server connections when TLS is enabled. The default Redis HAProxy image and digest also change.

Changes

Redis HAProxy TLS curve preferences

Layer / File(s) Summary
Derive curve preferences from the cluster TLS profile
argocd-operator/pkg/tlsprofile/profile.go, cmd/main.go
TLSConfigProfile adds CurvePreferences. Startup code copies cluster profile groups into the central TLS profile in order.
Map and apply HAProxy TLS curves
argocd-operator/common/defaults.go, argocd-operator/controllers/argoutil/redis.go, argocd-operator/build/redis/haproxy.cfg.tpl, build/redis/haproxy.cfg.tpl, argocd-operator/controllers/argoutil/redis_test.go
Redis HAProxy configuration maps supported curve names and passes nonempty results to the template. The template configures bind and server curves. The default HAProxy image and digest change. Tests cover mappings and rendered configurations.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant ClusterTLSProfile
  participant Main as cmd/main.go
  participant CentralProfile as CentralTLSConfigProfile
  participant RedisConfig as GetRedisHAProxyConfig
  participant CurveMapper as MapCurvePreferencesToHAProxyCurves
  participant HaproxyTemplate as haproxy.cfg.tpl
  ClusterTLSProfile->>Main: provides profile.Groups
  Main->>CentralProfile: sets CurvePreferences
  RedisConfig->>CurveMapper: maps CurvePreferences
  CurveMapper-->>RedisConfig: returns supported HAProxy curve names
  RedisConfig->>HaproxyTemplate: passes TLSCurves when nonempty
  HaproxyTemplate-->>HaproxyTemplate: configures bind and server curves
Loading

Suggested reviewers: olivergondza


Merge Risk: ⚪ Minimal · up to d25d8

The Redis HAProxy curve configuration appears ready to merge after normal checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 5 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Title check Passed The title clearly and concisely describes configuring TLS curve preferences for Redis HAProxy.
Description check Passed The description explains the TLS curve configuration, the HAProxy image upgrade for PQC support, testing guidance, and the linked issue.

Full details: Docstring Coverage

Explanation

Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 5 files. (2 skipped: 2 unsupported.)



  • Fix all pre-merge checks with AI

Comment @coderabbitai help to get the list of available commands.

@openshift-ci

openshift-ci Bot commented Oct 9, 2026

Copy link
Copy Markdown

@akhilnittala: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/v4.14-kuttl-parallel d25d8c6 link false /test v4.14-kuttl-parallel
ci/prow/v4.19-kuttl-sequential d25d8c6 link true /test v4.19-kuttl-sequential
ci/prow/v4.14-kuttl-sequential d25d8c6 link false /test v4.14-kuttl-sequential

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant