kubeblocks icon indicating copy to clipboard operation
kubeblocks copied to clipboard

[Improvement] Improve TLS function provided by KB

Open loomts opened this issue 1 year ago • 0 comments

  1. TLS file provided by KB is based on component, different components have different TLS files. However, some typologies have multiple components and they need to communicate with each other. Maybe we need to provide a larger scope of the TLS root certificate from component to cluster?

  2. Different replicas in one component share the same TLS file, and use a wildcard to match the hostname of the headless service. Is it needed to generate the unique TLS file for each replica of the same component?

loomts avatar Sep 24 '24 16:09 loomts