cli icon indicating copy to clipboard operation
cli copied to clipboard

[Helm] certificate lifecycle management

Open petermikitsh opened this issue 5 years ago • 0 comments

Currently, the helm <-> tiller connection is secured via TLS/SSL. We generate a Certificate Authority that's good for 20 years, a Helm certificate that's valid for 1 year, and a Tiller certificate that's also valid for 1 year.

Inevitably, the CA and Certificates are going to expire, and will need to be re-created, and their lifecycle managed accordingly. Practically speaking, since helm is only used during cluster creation, their expiration won't break deployments -- so this won't impact end users.

petermikitsh avatar Mar 12 '19 02:03 petermikitsh