internal: gRPC/HTTP collector TLS and mTLS (fork CI only) - #5
Open
songzhendong wants to merge 3 commits into
Open
internal: gRPC/HTTP collector TLS and mTLS (fork CI only)#5songzhendong wants to merge 3 commits into
songzhendong wants to merge 3 commits into
Conversation
Add SW_AGENT_FORCE_TLS and SSL CA/cert/key paths; share tls helpers across gRPC and HTTP; convert PKCS#1 keys to PKCS#8 for HTTP stacks that reject PKCS#1. Follow symlinks so Kubernetes secret mounts work. Never raise TLS misconfig into the host process: warn and degrade (plaintext / system trust / one-way TLS), including OSError from SSLContext load races and path expanduser/resolve failures. Validate CA and client PEMs when building material so bad content does not defer failure to connect time; FORCE_TLS fallback never attaches client certs, and credential build failure may warn and stay plaintext rather than abort start. Keep HTTP mTLS temp PEMs fork-safe via register_at_fork rebind. Drop test-only ssl_target_name_override; TLS peer-name follows grpc.default_authority. Generate e2e PEMs via shared gen-e2e-tls-certs.sh in digest-pinned alpine/openssl (no apk; PEMs not committed). mTLS e2e healthchecks the sharing-server port.
songzhendong
force-pushed
the
feat/grpc-http-tls-mtls
branch
17 times, most recently
from
September 12, 2026 14:14
5415056 to
a4dfb42
Compare
Extract PKCS#1 / CERTIFICATE PEM between BEGIN/END only so preamble and UTF-8 BOM cannot break b64decode or aio SSLContext cadata. Always verify HTTP with a process-lifetime CA temp snapshot (not the resolved K8s ..data path) so secret rotation cannot invalidate an open session.
When the HTTP CA snapshot cannot be written, fall back to the still-readable configured CA path instead of Requests' system trust store. Extract both CERTIFICATE and TRUSTED CERTIFICATE blocks (labels/trust attrs preserved) so openssl -trustout CAs remain usable for sync HTTPS; aio falls back to cafile when cadata rejects TRUSTED CERTIFICATE.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
skywalking/utils/tls.pyfor sync/aio gRPC and HTTP/aiohttp reportersTest plan
tests/unit/test_tls.pygRPC-ssl/gRPC-mtlsInternal fork CI only — not for apache upstream visibility.