-
-
Notifications
You must be signed in to change notification settings - Fork 8
fix: Prevent missing certificates #796
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
36 tasks
Member
Author
adwk67
reviewed
Sep 23, 2025
Member
adwk67
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just nits, really. Ran the nightly tests locally and all 👍
Co-authored-by: Andrew Kenworthy <1712947+adwk67@users.noreply.github.com>
Co-authored-by: Andrew Kenworthy <1712947+adwk67@users.noreply.github.com>
adwk67
approved these changes
Sep 23, 2025
Member
adwk67
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Part of stackabletech/issues#764
How to test
Create problem
_WORK/trino.yaml:The Trino Pod will not come up because of
backend failed to get secret data: failed to pick a CA: no CA in Secret.v1./secret-provisioner-short-tls-ca.stackable-operators will live until at least 2025-09-04 8:03:42.030007063 +00:00:00.That's totally expected!
Let's wait until the CA certificate Secrets have the desired amount of rotated certificates.
Afterwards increase the ca cert lifetime to start the Pod:
kubectl patch secretclass short-tls --type=merge --patch '{"spec": {"backend": {"autoTls": {"ca": {"caCertificateLifetime": "365d"}}}}}'Congrats, your secret-op now did a certificate rotation and your Pod should start up (after some time for retries)!
Debug commands
keytool -list -storepass "" -keystore /certs/pkcs12-1/truststore.p12 openssl pkcs12 -password pass: -in /certs/pkcs12-1/truststore.p12Definition of Done Checklist
Author
Reviewer
Acceptance
type/deprecationlabel & add to the deprecation scheduletype/experimentallabel & add to the experimental features tracker