15:00:21 #startmeeting openstack-helm 15:00:23 Meeting started Tue May 19 15:00:21 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:24 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:26 The meeting name has been set to 'openstack_helm' 15:00:33 #link https://etherpad.opendev.org/p/openstack-helm-weekly-meeting agenda 15:02:03 o/ 15:02:16 \o 15:02:39 o/ 15:05:07 Hello 15:05:07 Lets get started 15:05:16 #topic next week meeting 15:05:50 I plan on canceling next week's meeting since I will be out, if anyone wants to host then lemme know 15:06:10 #topic virtual ptg - june 15:06:22 Reminder that the OpenDev PTG is coming up in < 2 weeks 15:06:25 #link https://etherpad.opendev.org/p/openstack-helm-ptg-victoria 15:06:40 ^ add topics to discuss there, otherwise it might be a quiet conference call 15:06:41 :) 15:06:55 #topic TLS 15:07:02 pordirect: I assume this is you 15:07:08 :) 15:07:35 so - it think the planets are alining for internal tls 15:07:43 we have had a few rough starts on this before 15:08:10 but evaluating jetstacks cert manager, it looks to be the missing link in what was attempted before 15:08:30 id therefore like to propose that we use that to get this effort moving again 15:08:49 which we could break down into a couple of steps: 15:09:18 1) Jetstack Cert Manager 15:09:18 a) Chart 15:09:18 b) Deploy in gate with snakeoil ca 15:09:18 2) Chart updates 15:09:18 a) Add in option to create TLS cr, with required hostnames - ideally via htk macro similar to the ingress rule generator 15:09:19 b) Get tls certs generated for all internal services 15:09:19 c) Mount secrets into api pods 15:09:20 d) Enable tls and also set the ingress rule to support secure backends 15:10:09 jetstack looks interesting 15:10:49 its used by the cluster api and several other projects 15:11:53 hmm 15:12:15 any thoughts on this approach? 15:12:36 It's the best one we have so far 15:12:40 I need to read up on it 15:12:43 same 15:12:59 ok - please do 15:13:07 I assume this means we don't need that sidecar stuff from years ago? 15:13:08 I read about kube-lego before 15:13:12 but it has been a while 15:13:21 gagehugo: i think thats the next phase following this 15:13:25 lets make it simple 15:13:34 I guess they already have a chart 15:13:36 and then optimise 15:13:46 I will play around with it 15:14:09 this is a pretty similar approach to what i did on another openstack-on-k8s project 15:14:16 and it worked very well there 15:14:25 nice 15:14:29 though i was using dogtag/freeipa then ;) 15:15:07 if we can load the certs with the correct CN as secret, the rest should follow 15:16:13 but lemme play around with jetstack and read up on the docs 15:16:22 I will read up on it as well 15:16:34 and look at that chart 15:16:55 Me too. Would be cool to get mTLS working 15:18:13 we just need tls not mtls right? 15:20:01 I assume just TLS 15:21:38 Sorry, did I misunderstand? Is this for TLS within the cluster? 15:22:01 Maybe I a mixing my acronyms :) 15:23:00 Gotta read up in any case 15:24:18 portdirect: anything else for TLS? I think the path forward is to read up on jetstack for now 15:29:18 thanks everyone, have a good rest of the week 15:29:22 #endmeeting