ESO-417: Extends ExternalSecretsConfig with trustedCABundle for custom PKI#2011
ESO-417: Extends ExternalSecretsConfig with trustedCABundle for custom PKI#2011bharath-b-rh wants to merge 1 commit into
Conversation
|
@bharath-b-rh: This pull request references ESO-417 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
…m PKI Signed-off-by: Bharath B <bhb@redhat.com>
|
@bharath-b-rh: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
The enhancement proposal already described operand customization via
ExternalSecretsConfig(for example global annotations,componentConfig/revisionHistoryLimit, andoverrideEnv). This update extends that same proposal withspec.controllerConfig.trustedCABundle: optionalConfigMap-backed CA certificates for the external-secrets core controller TLS trust (alongside existing proxy/CNO behaviour), including validation, mount/SSL_CERT_DIRsemantics, CEL interaction withoverrideEnv, topology, tests, and support notes.