Conversation
When webhook serves HTTPS, ServeTLS loads the certificate once at startup and keeps serving it after the files on disk are renewed, so a renewed Let's Encrypt certificate is only picked up after a restart. With -secure -hotreload, the certificate and key are now loaded through tls.Config.GetCertificate, which checks the files' modification times on each handshake and reloads the pair when either changed. If reloading fails the previously loaded certificate keeps being served. Fixes adnanh#393
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #393
What
With
-secure, webhook loads the certificate/key once viaServeTLSand keeps serving that in-memory copy after the files are renewed on disk (e.g. by certbot), so a renewed Let's Encrypt certificate only takes effect after a restart.Fix
When
-secureis combined with-hotreload, the certificate is now served throughtls.Config.GetCertificate(certReloaderintls.go). On each handshake it compares the cert and key files' modification times with the ones it loaded; if either changed, it reloads the pair. If reloading fails (e.g. key temporarily missing mid-renewal), the previously loaded certificate keeps being served and the error is logged. Without-hotreloadbehaviour is unchanged.The
-hotreloadhelp text anddocs/Webhook-Parameters.mdmention the new behaviour.Tests
TestCertReloader(new,tls_test.go): generates a self-signed cert, checks the reloader returns it, rewrites cert+key with a new serial and checks the new one is served, then deletes the key and checks the last good certificate is still returned.webhook -secure -hotreload, connected with a TLS client, regenerated the cert withopenssl(serial 1 → 2), connected again.