zitadel-charts icon indicating copy to clipboard operation
zitadel-charts copied to clipboard

No imagePullPolicy for self signed SSL certificate container

Open bdalpe opened this issue 11 months ago • 1 comments

Preflight Checklist

  • [X] I could not find a solution in the existing issues, docs, nor discussions
  • [ ] I have joined the ZITADEL chat

Describe your problem

The chart does not have a configurable value for imagePullPolicy in the alpine/openssl initContainer. This causes the imagePullPolicy to be set to Always by default resulting in excessive pulling from Docker.

Describe your ideal solution

As a user of the Helm Chart, I want to be able to configure the imagePullPolicy for the self signed certificate generation.

Version

7.6.1

App version

v2.46.0

Additional Context

Why not consider using Helm's built-in [genSelfSignedCert](https://helm.sh/docs/chart_template_guide/function_list/#genselfsignedcert) function? This eliminates the need for the initContainer all together

bdalpe avatar Mar 20 '24 16:03 bdalpe

Thank you for sharing your idea. If there is a significant demand from customers/community, we will carefully consider implementing the feature. Currently, the issue will be added to our product backlog to collect feedback.

hifabienne avatar Mar 21 '24 06:03 hifabienne

Why not consider using Helm's built-in genSelfSignedCert function? This eliminates the need for the initContainer all together

I was not aware of this function. Actually, I like this approach more so we can get rid of the init container. @bdalpe would you mind creating an issue for that and close this one?

eliobischof avatar Jun 13 '24 10:06 eliobischof

Why not consider using Helm's built-in genSelfSignedCert function? This eliminates the need for the initContainer all together

I don't like it and prefer to use cert-manager which in fact is almost the essential component of many clusters.

gecube avatar Jun 16 '24 12:06 gecube

@eliobischof I will close this and also reference @gecube's cert-manager request.

@gecube, I agree with you that cert-manager should be used, but there also needs to be a simple way to test this chart without the dependency of cert-manager being installed.

I will add my thoughts in a new ticket.

bdalpe avatar Jun 17 '24 16:06 bdalpe