-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Closed
Labels
team: devxteam: webappIssue belongs to the WebApp teamIssue belongs to the WebApp teamteam: workspaceIssue belongs to the Workspace teamIssue belongs to the Workspace team
Milestone
Description
The certificate we use as CA for generating our cluster internal certificates will expire on 1st of April, 2022.
A derivative (in-cluster secrets are called ws-manager-tls and ws-manager-client-tls) is used most prominently by ws-manager and all it's clients for mTLS on the ws-manger interface. This is important, because that's what we configure in the DBWorkspaceCluster database!
Steps we need to do before 1st of April, ideally within next week to not interfere with the Offsite:
- webapp: verify that we do not rely on those for (non-local) connections to
ws-manager - platform: create a new certificate, and place that in Google Secret manager
⚠️ we must not run a TF script on the app clusters after this!
- workspace: deploy a new set of WorkspaceClusters, and register those in the DB
- workspace: shift workspace traffic to the new clusters
- platform: run TF scripts to update the CA in app clusters
- webapp: re-deploy webapp with new CA (incl. workspace components in app cluster)
@kylos101 For the new workspace cluster creation
@meysholdt @mads-hartmann for being aware of this, and the platform parts
@jldec @JanKoehnlein For team WebApp
@wulfthimm Thx for making us aware again! 🙏
Metadata
Metadata
Assignees
Labels
team: devxteam: webappIssue belongs to the WebApp teamIssue belongs to the WebApp teamteam: workspaceIssue belongs to the Workspace teamIssue belongs to the Workspace team
Type
Projects
Status
No status