Skip to content

feat: support GCP Private CA as TLS automation cert issuer - #522

Merged
clement0010 merged 79 commits into
masterfrom
feat/ct/tls-gcp-ca
Sep 15, 2026
Merged

clement0010 merged 79 commits into
masterfrom
feat/ct/tls-gcp-ca

Conversation

@clement0010

@clement0010 clement0010 commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Related Tickets

Issue: #423

Changes

  • Support tls.automation.issuer.gcpPrivateCA config. When configured, Gateway issues downstream TLS certs through a Google Cloud CA Service pool, and verifies each issued cert the same way the Vault issuer does: exact requested DNS/IP SANs, TTL and public key.
  • Credentials come from a service account key file, or from Application Default Credentials when none is configured.

clement0010 and others added 30 commits July 24, 2026 17:42
BREAKING CHANGE: the downstream TLS certificate settings moved from
tls.certificateFile/tls.privateKeyFile to tls.static.certificateFile/
tls.static.privateKeyFile. Behavior is unchanged; the Helm chart renders
the new layout. Prepares the schema for the mutually exclusive
tls.dynamic mode (#423).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X9Z4JjodvSrpkMw964Lcgx
- add tls.automation.issuer.vault, issuing leaf certificates through Vault's
  PKI secrets engine alongside the existing local CA issuer
- share the Vault client, auth and token-renewal code between the TLS and
  SSH CAs in a new internal/vault package
- issue DNS SANs only; the no-SNI local-address fallback still serves probes,
  which skip verification

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Health probes dial the gateway by IP without SNI, so the local-address
fallback requests a certificate for a bare IP. Split IP aliases into
ip_sans when issuing through Vault so those certificates verify, matching
the self-sign issuer.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 10, 2026 11:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 7 changed files in this pull request and generated 2 comments.

Comment thread internal/connect/cert/issuer_test.go
Comment thread internal/connect/cert/issuer.go
Copilot AI review requested due to automatic review settings September 15, 2026 03:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 7 changed files in this pull request and generated 1 comment.

Suppressed comments (1)

internal/config/config.go:153

  • The YAML loading path is not covered for these new optional fields: the existing TestLoad_TLSAutomation only unmarshals a local issuer, while the added tests construct TLSGCPPrivateCAIssuerConfig directly. A regression in either tag would silently drop issuingCertificateAuthorityID or credentialsFile, causing issuance to use a different CA or ADC instead of the operator's configured credentials. Add a Load test that asserts both values are populated from YAML.
	IssuingCertificateAuthorityID string `yaml:"issuingCertificateAuthorityID,omitempty"`

	CredentialsFile string `yaml:"credentialsFile,omitempty"` // Defaults to Application Default Credentials

Comment thread internal/connect/cert/issuer.go
Base automatically changed from feat/ct/tls-vault-ca to master September 15, 2026 04:08
Copilot AI review requested due to automatic review settings September 15, 2026 04:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

internal/config/config.go:131

  • Please add a YAML load test for this new issuer. The current config tests only construct TLSGCPPrivateCAIssuerConfig values directly, so the user-facing gcpPrivateCA and nested tags (caPoolID, the optional issuing-CA ID, and credentials file) are not exercised; a YAML tag typo would pass the suite. Extend TestLoad_TLSAutomation with a GCP block and assert all fields.
	GCPPrivateCA *TLSGCPPrivateCAIssuerConfig `yaml:"gcpPrivateCA,omitempty"`

internal/connect/cert/issuer.go:304

  • Please add coverage for the empty CredentialsFile branch. The new tests exercise a service-account file and a missing file, but none runs run without a credentials file, so a regression that disables the documented ADC/workload-identity fallback would go unnoticed. Use a controlled ADC fixture (for example GOOGLE_APPLICATION_CREDENTIALS) rather than relying on the test runner's ambient credentials.
	if g.credentialsFile != "" {
		opts = append(opts, option.WithAuthCredentialsFile(option.ServiceAccount, g.credentialsFile))
	}

internal/connect/cert/issuer.go:348

  • pem_certificate_chain from Certificate Authority Service already contains the leaf certificate (the API documents it as the full chain, leaf first). Prepending PemCertificate here therefore returns the leaf twice; automation.issue will send that duplicate as an intermediate, which can make downstream TLS clients reject the chain. Parse the returned chain directly (and update the fake response in the test to include the leaf first).
	chain, err := parseCertificateChain(append([]string{issued.GetPemCertificate()}, issued.GetPemCertificateChain()...))

@clement0010
clement0010 enabled auto-merge (squash) September 15, 2026 04:23
@clement0010
clement0010 merged commit ee8dfc2 into master Sep 15, 2026
14 checks passed
@clement0010
clement0010 deleted the feat/ct/tls-gcp-ca branch September 15, 2026 04:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants