Repository navigation
Configure certificates subject - #714
Conversation
lhotari
left a comment
There was a problem hiding this comment.
This looks good. I verified locally that the default render is byte-identical to master, the subject block maps correctly onto cert-manager's X509Subject, an empty subject renders nothing rather than subject: null, and values.yaml carries no organization remnant that could trip the guard spuriously.
Render recipe I used, if useful:
helm dependency build charts/pulsar
helm template test charts/pulsar --set "tls.enabled=true,tls.broker.enabled=true,\
tls.proxy.enabled=true,tls.zookeeper.enabled=true,tls.bookie.enabled=true,\
certs.internal_issuer.enabled=true,components.proxy=true" -s templates/tls-certs-internal.yaml
I initially wanted to push back on two things and talked myself out of both — see the inline notes.
One request before merge: document the migration
The diff touches only _certs.tpl and values.yaml. The README's upgrade procedure explicitly says helm get values … > values.yaml and reuse it, which is exactly the path that now aborts. There's good precedent to follow: the "Upgrading to Helm chart version 4.1.0" section covers the structurally identical auth.authentication.provider removal.
Could you add a README "Upgrading to Helm chart version 4.8.0" section showing the before/after:
# before
tls:
common:
organization:
- pulsar
# after
tls:
common:
subject:
organizations:
- pulsarApproving so this isn't blocked on me — please land the docs before merging.
Note
#713 also edits _certs.tpl. git merge-tree shows no textual conflict at the current heads, but whichever lands second should be rebased and re-rendered.
Reviewed with Codex gpt-5.6-sol and Claude Opus 5; every finding reproduced locally by rendering the chart.
|
Migration documented in 79b949b |
lhotari
left a comment
There was a problem hiding this comment.
LGTM. Thanks for adding the commented-out X509Subject fields and the upgrade note. Both address my earlier feedback.
# Conflicts: # README.md
Motivation
Currently only certificates subject organizations is configurable.
This PR allow to configure full subject properties.
Modifications
Move
tls.common.organizationtotls.common.subject.organizations.Fail if
tls.common.organizationis still used.Verifying this change