Skip to content

[DPE-10608] Operator-cert manager, events handler + release (3/4) - #174

Closed
marceloneppel wants to merge 3 commits into
tls-1-statefrom
tls-3-manager-events
Closed

marceloneppel wants to merge 3 commits into
tls-1-statefrom
tls-3-manager-events

Conversation

@marceloneppel

@marceloneppel marceloneppel commented Jul 1, 2026 •

Copy link
Copy Markdown
Member

Part 3/4, stacked on tls-2-state-accessors. Wires the operator-certificate manager + events handler into the lib charm — the core of the live-fetch TLS subsystem — and bumps the library version.

What's here

  • managers/tls.py (TLSManager): live-fetch getters (get_client_tls_files / get_peer_tls_files / get_peer_ca_bundle call get_assigned_certificates() on demand — operator cert/key are never persisted), push_tls_files, rotate_peer_ca / clear_peer_ca (only the peer CA is tracked in state, for the rotation bundle), internal-peer CA/cert generation, and client_tls_files_on_disk.
  • events/tls.py (TLS): owns the two TLSCertificatesRequiresV4 requirers, observes certificate_available + relation_broken, defers the file-push until the workload is ready, re-requests certs on SAN changes. Reaches the manager via self.charm.tls_manager.
  • charms/abstract_charm.py: builds TLS first, then TLSManager with the handler's requirers injected.
  • pyproject.toml + uv.lock: bump to 16.3.3.

Layer the certificate-SAN and common-name policy onto CharmState, on top of the raw peer-databag accessors from the previous branch, so the substrate-specific certificate identity is reviewable as a unit with its own tests before any manager or handler consumes it.

K8s must regain the parity the migration had dropped: common_hosts has to advertise the primary/replicas Service FQDNs and the resolved pod FQDN, and the operator-cert common name has to be the endpoints FQDN (wildcarded past the 64-char CN limit) rather than the VM-style host/address; the peer SAN set must exclude the ip key the original K8s charm never emitted. VM behaviour is left host/address-derived as before. The CharmState charm parameter is also widened to ops.CharmBase so the state object no longer depends on the concrete charm type.

These accessors are additive and only read state, so the existing charm keeps constructing unchanged.

Signed-off-by: Marcelo Henrique Neppel <marcelo.neppel@canonical.com>
@marceloneppel
marceloneppel force-pushed the tls-2-state-accessors branch from 1dd22a8 to c6aa083 Compare July 3, 2026 20:27
@marceloneppel
marceloneppel force-pushed the tls-3-manager-events branch from d59f0ac to 1f84b9c Compare July 3, 2026 20:27
…cstring

The 'migration had switched this to VM-style ...; restore the endpoints-FQDN
CN for K8s parity' sentence narrates a completed regression fix and is
redundant with the preceding 'Matches the original K8s charm' line. The
format, wildcard rule, and parity rationale already carry the load-bearing
context; the migration history belongs in the original commit message, not
the docstring.

Signed-off-by: Marcelo Henrique Neppel <marcelo.neppel@canonical.com>
@marceloneppel marceloneppel changed the title feat(tls): operator-cert manager, events handler + release (3/4) [DPE-10608] feat(tls): operator-cert manager, events handler + release (3/4) Jul 7, 2026
@marceloneppel marceloneppel changed the title [DPE-10608] feat(tls): operator-cert manager, events handler + release (3/4) [DPE-10608] Operator-cert manager, events handler + release (3/4) Jul 7, 2026
Wire the operator-certificate TLSManager and TLS events handler into the lib
charm and bump the library version. The manager fetches operator cert/key live
from the tls_certificates V4 requirers (constructor-injected by the handler);
only the peer CA is tracked in state for rotation. Unit tests for this layer
land in the stacked tests PR.

Signed-off-by: Marcelo Henrique Neppel <marcelo.neppel@canonical.com>
@marceloneppel
marceloneppel force-pushed the tls-3-manager-events branch from 1f84b9c to f78c998 Compare July 7, 2026 19:28
Base automatically changed from tls-2-state-accessors to tls-1-state July 9, 2026 12:34
@marceloneppel
marceloneppel deleted the branch tls-1-state July 9, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant