fix: separate TLS inputs and preserve certificate reloads (#1653)

Co-authored-by: Alessandro (Ale) Segala <43508+ItalyPaleAle@users.noreply.github.com>
This commit is contained in:
Elias Schneider
2026-08-07 00:32:08 +00:00
committed by GitHub
co-authored by Alessandro Segala
parent 1f9cc5e58e
commit 06ccadfcd0
7 changed files with 300 additions and 60 deletions
+3 -2
View File
@@ -72,9 +72,10 @@ func init() {
rootCmd.AddCommand(healthcheckCmd)
}
// The server only serves TLS when both a certificate and a key file are configured
// The server serves TLS when either inline certificate data or certificate files are configured
func tlsEnabled() bool {
return common.EnvConfig.TLSCertFile != "" && common.EnvConfig.TLSKeyFile != ""
return (common.EnvConfig.TLSCert != "" && common.EnvConfig.TLSKey != "") ||
(common.EnvConfig.TLSCertFile != "" && common.EnvConfig.TLSKeyFile != "")
}
func defaultEndpoint() string {
+18
View File
@@ -152,6 +152,11 @@ func TestDefaultEndpoint(t *testing.T) {
setTLSFiles(t)
assert.Equal(t, "https://localhost:"+common.EnvConfig.Port, defaultEndpoint())
})
t.Run("uses https if inline TLS certificate data is configured", func(t *testing.T) {
setInlineTLS(t)
assert.Equal(t, "https://localhost:"+common.EnvConfig.Port, defaultEndpoint())
})
}
// t.TempDir embeds the test name, which can exceed the maximum socket path length
@@ -180,6 +185,19 @@ func setTLSFiles(t *testing.T) {
common.EnvConfig.TLSKeyFile = "key.pem"
}
// Only the presence of the data matters because the healthcheck never parses the certificate
func setInlineTLS(t *testing.T) {
t.Helper()
cert, key := common.EnvConfig.TLSCert, common.EnvConfig.TLSKey
t.Cleanup(func() {
common.EnvConfig.TLSCert, common.EnvConfig.TLSKey = cert, key
})
common.EnvConfig.TLSCert = "certificate"
common.EnvConfig.TLSKey = "private key"
}
func newSelfSignedTLSConfig(t *testing.T) *tls.Config {
t.Helper()