Repository navigation
[DPE-10608] Operator-cert manager, events handler + release (3/4) - #174
Closed
marceloneppel wants to merge 3 commits into
Closed
marceloneppel wants to merge 3 commits into
marceloneppel wants to merge 3 commits into
Conversation
marceloneppel
force-pushed
the
tls-2-state-accessors
branch
from
July 2, 2026 17:46
c7fcfd1 to
f01bfee
Compare
marceloneppel
force-pushed
the
tls-3-manager-events
branch
from
July 2, 2026 17:46
90e7728 to
ab4b0c8
Compare
marceloneppel
force-pushed
the
tls-2-state-accessors
branch
from
July 2, 2026 18:23
f01bfee to
1dd22a8
Compare
marceloneppel
force-pushed
the
tls-3-manager-events
branch
from
July 2, 2026 18:23
ab4b0c8 to
d59f0ac
Compare
Layer the certificate-SAN and common-name policy onto CharmState, on top of the raw peer-databag accessors from the previous branch, so the substrate-specific certificate identity is reviewable as a unit with its own tests before any manager or handler consumes it. K8s must regain the parity the migration had dropped: common_hosts has to advertise the primary/replicas Service FQDNs and the resolved pod FQDN, and the operator-cert common name has to be the endpoints FQDN (wildcarded past the 64-char CN limit) rather than the VM-style host/address; the peer SAN set must exclude the ip key the original K8s charm never emitted. VM behaviour is left host/address-derived as before. The CharmState charm parameter is also widened to ops.CharmBase so the state object no longer depends on the concrete charm type. These accessors are additive and only read state, so the existing charm keeps constructing unchanged. Signed-off-by: Marcelo Henrique Neppel <marcelo.neppel@canonical.com>
marceloneppel
force-pushed
the
tls-2-state-accessors
branch
from
July 3, 2026 20:27
1dd22a8 to
c6aa083
Compare
marceloneppel
force-pushed
the
tls-3-manager-events
branch
from
July 3, 2026 20:27
d59f0ac to
1f84b9c
Compare
…cstring The 'migration had switched this to VM-style ...; restore the endpoints-FQDN CN for K8s parity' sentence narrates a completed regression fix and is redundant with the preceding 'Matches the original K8s charm' line. The format, wildcard rule, and parity rationale already carry the load-bearing context; the migration history belongs in the original commit message, not the docstring. Signed-off-by: Marcelo Henrique Neppel <marcelo.neppel@canonical.com>
Wire the operator-certificate TLSManager and TLS events handler into the lib charm and bump the library version. The manager fetches operator cert/key live from the tls_certificates V4 requirers (constructor-injected by the handler); only the peer CA is tracked in state for rotation. Unit tests for this layer land in the stacked tests PR. Signed-off-by: Marcelo Henrique Neppel <marcelo.neppel@canonical.com>
marceloneppel
force-pushed
the
tls-3-manager-events
branch
from
July 7, 2026 19:28
1f84b9c to
f78c998
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 3/4, stacked on tls-2-state-accessors. Wires the operator-certificate manager + events handler into the lib charm — the core of the live-fetch TLS subsystem — and bumps the library version.
What's here
managers/tls.py(TLSManager): live-fetch getters (get_client_tls_files/get_peer_tls_files/get_peer_ca_bundlecallget_assigned_certificates()on demand — operator cert/key are never persisted),push_tls_files,rotate_peer_ca/clear_peer_ca(only the peer CA is tracked in state, for the rotation bundle), internal-peer CA/cert generation, andclient_tls_files_on_disk.events/tls.py(TLS): owns the twoTLSCertificatesRequiresV4requirers, observescertificate_available+relation_broken, defers the file-push until the workload is ready, re-requests certs on SAN changes. Reaches the manager viaself.charm.tls_manager.charms/abstract_charm.py: buildsTLSfirst, thenTLSManagerwith the handler's requirers injected.pyproject.toml+uv.lock: bump to16.3.3.