Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions cmd/controller/app/controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -358,6 +358,7 @@ func buildControllerContextFactory(ctx context.Context, opts *config.ControllerC
DefaultIssuerGroup: opts.IngressShimConfig.DefaultIssuerGroup,
DefaultAutoCertificateAnnotations: opts.IngressShimConfig.DefaultAutoCertificateAnnotations,
ExtraCertificateAnnotations: opts.IngressShimConfig.ExtraCertificateAnnotations,
GatewayAPIExtraProtocols: sets.New[string](opts.GatewayAPIConfig.ExtraProtocols...),
},

CertificateOptions: controller.CertificateOptions{
Expand Down
4 changes: 4 additions & 0 deletions cmd/controller/app/options/options.go
Original file line number Diff line number Diff line change
Expand Up @@ -177,6 +177,10 @@ func AddConfigFlags(fs *pflag.FlagSet, c *config.ControllerConfiguration) {
fs.BoolVar(&c.EnableGatewayAPIListenerSet, "enable-gateway-api-listenerset", c.EnableGatewayAPIListenerSet, ""+
"Whether ListenerSets support is enabled within cert-manager. The ListenerSet "+
"feature gate must also be enabled.")
fs.StringSliceVar(&c.GatewayAPIConfig.ExtraProtocols, "gateway-api-extra-protocols", c.GatewayAPIConfig.ExtraProtocols, ""+
"A comma-separated list of additional Gateway Listener protocol types that the Gateway API shim should treat as TLS-capable. "+
"By default, only HTTPS and TLS protocol types are processed. Each entry must exactly match the protocol string as it appears "+
"on the Gateway Listener, e.g. 'DTLS'.")
fs.StringSliceVar(&c.CopiedAnnotationPrefixes, "copied-annotation-prefixes", c.CopiedAnnotationPrefixes, "Specify which annotations should/shouldn't be copied"+
"from Certificate to CertificateRequest and Order, as well as from CertificateSigningRequest to Order, by passing a list of annotation key prefixes."+
"A prefix starting with a dash(-) specifies an annotation that shouldn't be copied. Example: '*,-kubectl.kubernetes.io/'- all annotations"+
Expand Down
11 changes: 11 additions & 0 deletions internal/apis/config/controller/types.go
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,9 @@ type ControllerConfiguration struct {
// PEMSizeLimitsConfig configures the maximum sizes for PEM-encoded data
PEMSizeLimitsConfig PEMSizeLimitsConfig

// GatewayAPIConfig configures the behaviour of the Gateway API integration
GatewayAPIConfig GatewayAPIConfig

// CertificateRequestMinimumBackoffDuration configures the initial backoff duration
// when a certificate request fails. This duration is exponentially increased (up to
// a maximum of 32 hours) based on the number of consecutive failures and represents
Expand Down Expand Up @@ -238,6 +241,14 @@ type ACMEDNS01Config struct {
CheckRetryPeriod time.Duration
}

type GatewayAPIConfig struct {
// ExtraProtocols is a list of additional Gateway Listener protocol types that
// the Gateway API shim should treat as TLS-capable. By default, only HTTPS
// and TLS protocol types are processed. Each entry must exactly match the
// protocol string as it appears on the Gateway Listener, e.g. "DTLS".
ExtraProtocols []string
Comment thread
ThatsMrTalbot marked this conversation as resolved.
}

type PEMSizeLimitsConfig struct {
// Maximum size for a single PEM-encoded certificate (in bytes).
// Defaults to 36500 bytes.
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

22 changes: 22 additions & 0 deletions internal/apis/config/controller/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions make/e2e-setup.mk
Original file line number Diff line number Diff line change
Expand Up @@ -315,7 +315,7 @@ e2e-setup-certmanager: e2e-setup-gatewayapi $(E2E_SETUP_OPTION_DEPENDENCIES) $(b
$(addprefix --version=,$(E2E_CERT_MANAGER_VERSION)) \
--set crds.enabled=true \
--set featureGates="$(feature_gates_controller)" \
--set "extraArgs={--kube-api-qps=9000,--kube-api-burst=9000,--concurrent-workers=200,--enable-gateway-api,--enable-gateway-api-listenerset}" \
--set "extraArgs={--kube-api-qps=9000,--kube-api-burst=9000,--concurrent-workers=200,--enable-gateway-api,--enable-gateway-api-listenerset,--gateway-api-extra-protocols=DTLS}" \
--set webhook.featureGates="$(feature_gates_webhook)" \
--set "cainjector.extraArgs={--feature-gates=$(feature_gates_cainjector)}" \
--set "dns01RecursiveNameservers=$(SERVICE_IP_PREFIX).16:53" \
Expand Down Expand Up @@ -343,7 +343,7 @@ e2e-setup-certmanager: $(bin_dir)/cert-manager.tgz $(foreach binaryname,controll
--set startupapicheck.image.tag="$(TAG)" \
--set crds.enabled=true \
--set featureGates="$(feature_gates_controller)" \
--set "extraArgs={--kube-api-qps=9000,--kube-api-burst=9000,--concurrent-workers=200,--enable-gateway-api,--enable-gateway-api-listenerset}" \
--set "extraArgs={--kube-api-qps=9000,--kube-api-burst=9000,--concurrent-workers=200,--enable-gateway-api,--enable-gateway-api-listenerset,--gateway-api-extra-protocols=DTLS}" \
--set webhook.featureGates="$(feature_gates_webhook)" \
--set "cainjector.extraArgs={--feature-gates=$(feature_gates_cainjector)}" \
--set "dns01RecursiveNameservers=$(SERVICE_IP_PREFIX).16:53" \
Expand Down
1 change: 1 addition & 0 deletions make/e2e.sh
Original file line number Diff line number Diff line change
Expand Up @@ -207,5 +207,6 @@ trace ginkgo \
--acme-gateway-ip="${SERVICE_IP_PREFIX}.14" \
--ingress-controller-domain=ingress-nginx.http01.example.com \
--gateway-domain=gateway.http01.example.com \
--gateway-api-extra-protocols=DTLS \
--feature-gates="$feature_gates" \
"${ginkgo_args[@]}"
11 changes: 11 additions & 0 deletions pkg/apis/config/controller/v1alpha1/types.go
Original file line number Diff line number Diff line change
Expand Up @@ -145,6 +145,9 @@ type ControllerConfiguration struct {
// pemSizeLimitsConfig configures the maximum sizes for PEM-encoded data
PEMSizeLimitsConfig PEMSizeLimitsConfig `json:"pemSizeLimitsConfig,omitzero"`

// gatewayAPI configures the behaviour of the Gateway API integration
GatewayAPIConfig GatewayAPIConfig `json:"gatewayAPI,omitzero"`

// CertificateRequestMinimumBackoffDuration configures the initial backoff duration
// when a certificate request fails. This duration is exponentially increased
// (up to a maximum of 32 hours) based on the number of consecutive failures.
Expand Down Expand Up @@ -240,6 +243,14 @@ type ACMEDNS01Config struct {
CheckRetryPeriod *sharedv1alpha1.Duration `json:"checkRetryPeriod,omitempty"`
}

type GatewayAPIConfig struct {
// ExtraProtocols is a list of additional Gateway Listener protocol types that
// the Gateway API shim should treat as TLS-capable. By default, only HTTPS
// and TLS protocol types are processed. Each entry must exactly match the
// protocol string as it appears on the Gateway Listener, e.g. "DTLS".
ExtraProtocols []string `json:"extraProtocols,omitempty"`
}

type PEMSizeLimitsConfig struct {
// Maximum size for a single PEM-encoded certificate (in bytes).
// Defaults to 36500 bytes.
Expand Down
22 changes: 22 additions & 0 deletions pkg/apis/config/controller/v1alpha1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

18 changes: 15 additions & 3 deletions pkg/controller/certificate-shim/sync.go
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ import (
"k8s.io/apimachinery/pkg/labels"
"k8s.io/apimachinery/pkg/runtime"
"k8s.io/apimachinery/pkg/runtime/schema"
"k8s.io/apimachinery/pkg/util/sets"
"k8s.io/apimachinery/pkg/util/validation/field"
"k8s.io/client-go/tools/record"
"k8s.io/utils/ptr"
Expand Down Expand Up @@ -137,7 +138,7 @@ func SyncFnFor(
}

extraAnnotations := extractExtraAnnotations(ingLike, defaults.ExtraCertificateAnnotations)
newCrts, updateCrts, err := buildCertificates(rec, log, cmLister, ingLike, issuerName, issuerKind, issuerGroup, extraAnnotations)
newCrts, updateCrts, err := buildCertificates(rec, log, cmLister, ingLike, issuerName, issuerKind, issuerGroup, extraAnnotations, defaults)
if err != nil {
return err
}
Expand Down Expand Up @@ -310,13 +311,24 @@ func validateGatewayListenerBlock(path *field.Path, l gwapi.Listener, ingLike me
return errs
}

// isGatewayAPITLSProtocol reports whether protocol is a TLS-capable Gateway
// listener protocol. It returns true for the built-in types (HTTPS and TLS) and
// for any value in extra. The comparison is case-sensitive.
func isGatewayAPITLSProtocol(protocol gwapi.ProtocolType, extra sets.Set[string]) bool {
if protocol == gwapi.HTTPSProtocolType || protocol == gwapi.TLSProtocolType {
return true
}
return extra.Has(string(protocol))
}

func buildCertificates(
rec record.EventRecorder,
log logr.Logger,
cmLister cmlisters.CertificateLister,
ingLike metav1.Object,
issuerName, issuerKind, issuerGroup string,
annotations map[string]string,
defaults controller.IngressShimOptions,
) (newCrts, updateCrts []*cmapi.Certificate, _ error) {
tlsHosts := make(map[corev1.ObjectReference][]string)
switch ingLike := ingLike.(type) {
Expand All @@ -335,7 +347,7 @@ func buildCertificates(
}
case *gwapi.ListenerSet:
for i, l := range ingLike.Spec.Listeners {
if l.Protocol != gwapi.HTTPSProtocolType && l.Protocol != gwapi.TLSProtocolType {
if !isGatewayAPITLSProtocol(l.Protocol, defaults.GatewayAPIExtraProtocols) {
continue
}

Expand Down Expand Up @@ -365,7 +377,7 @@ func buildCertificates(
case *gwapi.Gateway:
for i, l := range ingLike.Spec.Listeners {
// TLS is only supported for a limited set of protocol types: https://gateway-api.sigs.k8s.io/guides/tls/#listeners-and-tls
Comment thread
ThatsMrTalbot marked this conversation as resolved.
if l.Protocol != gwapi.HTTPSProtocolType && l.Protocol != gwapi.TLSProtocolType {
if !isGatewayAPITLSProtocol(l.Protocol, defaults.GatewayAPIExtraProtocols) {
continue
}

Expand Down
Loading