Skip to content

internal: gRPC/HTTP collector TLS and mTLS (fork CI only) - #5

Open
songzhendong wants to merge 3 commits into
masterfrom
feat/grpc-http-tls-mtls
Open

internal: gRPC/HTTP collector TLS and mTLS (fork CI only)#5
songzhendong wants to merge 3 commits into
masterfrom
feat/grpc-http-tls-mtls

Conversation

@songzhendong

Copy link
Copy Markdown
Owner

Summary

  • Collector TLS/mTLS for gRPC and HTTP: FORCE_TLS, optional CA, optional client cert+key
  • Shared skywalking/utils/tls.py for sync/aio gRPC and HTTP/aiohttp reporters
  • Hardening: follow secret-mount symlinks, 256 KiB PEM cap; missing mTLS material stays one-way TLS (no abort)

Test plan

  • Fork CI
  • Unit: tests/unit/test_tls.py
  • Real-OAP e2e: gRPC-ssl / gRPC-mtls

Internal fork CI only — not for apache upstream visibility.

Add SW_AGENT_FORCE_TLS and SSL CA/cert/key paths; share tls helpers across
gRPC and HTTP; convert PKCS#1 keys to PKCS#8 for HTTP stacks that reject
PKCS#1. Follow symlinks so Kubernetes secret mounts work. Never raise TLS
misconfig into the host process: warn and degrade (plaintext / system trust /
one-way TLS), including OSError from SSLContext load races and path
expanduser/resolve failures. Validate CA and client PEMs when building
material so bad content does not defer failure to connect time; FORCE_TLS
fallback never attaches client certs, and credential build failure may warn
and stay plaintext rather than abort start. Keep HTTP mTLS temp PEMs
fork-safe via register_at_fork rebind. Drop test-only
ssl_target_name_override; TLS peer-name follows grpc.default_authority.
Generate e2e PEMs via shared gen-e2e-tls-certs.sh in digest-pinned
alpine/openssl (no apk; PEMs not committed). mTLS e2e healthchecks the
sharing-server port.
@songzhendong
songzhendong force-pushed the feat/grpc-http-tls-mtls branch 17 times, most recently from 5415056 to a4dfb42 Compare September 12, 2026 14:14
Extract PKCS#1 / CERTIFICATE PEM between BEGIN/END only so preamble and
UTF-8 BOM cannot break b64decode or aio SSLContext cadata. Always verify
HTTP with a process-lifetime CA temp snapshot (not the resolved K8s
..data path) so secret rotation cannot invalidate an open session.
When the HTTP CA snapshot cannot be written, fall back to the still-readable
configured CA path instead of Requests' system trust store. Extract both
CERTIFICATE and TRUSTED CERTIFICATE blocks (labels/trust attrs preserved) so
openssl -trustout CAs remain usable for sync HTTPS; aio falls back to cafile
when cadata rejects TRUSTED CERTIFICATE.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant