Skip to content

Add TLS, external service, and plugin support - #1 - #26

Merged
robfrank merged 3 commits into
ArcadeData:mainfrom
rlaveycal:tls
Oct 6, 2026
Merged

robfrank merged 3 commits into
ArcadeData:mainfrom
rlaveycal:tls

Conversation

@rlaveycal

@rlaveycal rlaveycal commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add Bolt plugin support and include enabled plugin ports in Services and NetworkPolicies.
  • Remove ports from HA server list as they're not necessary and all nodes have the same ports
  • Explicitly set HTTP and HTTPS ports from chart values.
  • Add HTTPS/TLS wiring and cert-manager Certificate resource,
  • Add an external Service that exposes HTTP and plugin ports.
  • Add StatefulSet metadata options and update Helm tests and chart documentation.
  • Mount optional config maps for backup and MCP JSON files

Validation

  • helm unittest . (179 tests)
  • helm lint charts/arcadedb

include plugin ports in network policy
add staefulset annotaions and labels
add https and tls settings
add cert-manager certificate
add backup and mcp config support
@rlaveycal

Copy link
Copy Markdown
Contributor Author

@robfrank do you want me to address #27 in this PR?

@robfrank

Copy link
Copy Markdown
Contributor

@robfrank do you want me to address #27 in this PR?

no, I prefer a dedicated one

@robfrank

Copy link
Copy Markdown
Contributor

I'll check the pr again tomorrow, but it looks good.

- Certificate keystore password follows the configured root password
  secret, or a dedicated tls.secretRef.passwordSecret
- Store passwords injected via a secretKeyRef env var, not inline args
- issuerProvidesCA=false falls back to keystore.p12 as trust store for
  issuers that return no ca.crt (truststore.p12 is otherwise missing)
- Certificate SANs cover the -http and -external services
- Expose HTTPS on the -http service
- TLS secret defaults to release-scoped <fullname>-tls; issuer name is
  required instead of a placeholder
- Restore host:raftPort:httpPort in ha.serverList (plus :0:httpsPort
  with TLS); certificate uses a separate port-less nodehosts helper
- Keep the <fullname>-http NetworkPolicy name, document opened ports
- PID/XDG cache paths follow arcadedb.tmpDirectory
- Only emit the external Service separator when it is rendered

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@robfrank
robfrank merged commit 9b58939 into ArcadeData:main Oct 6, 2026
3 checks passed
@robfrank

robfrank commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thanks @rlaveycal, this is merged! Bolt, the external service, TLS and the cert-manager integration are all really useful additions.

Before merging I pushed a follow-up commit (61c89b7) to your branch after a review. Heads-up on what changed, in case you're already using these values:

Values that changed

  • tls.secretRef.password was removed. The store password is now read from a Secret and passed in through a TLS_STORE_PASSWORD env var, so it no longer appears in the pod spec. By default it uses the root password Secret (including a user-supplied one). Use tls.secretRef.passwordSecret.{name,key} to point at a different Secret.
  • tls.secretRef.name now defaults to <fullname>-tls instead of arcadedb-tls, so two releases in the same namespace don't share a secret.
  • tls.certManager.issuerRef.name no longer defaults to my-issuer and is now required when cert-manager is enabled.
  • New tls.certManager.issuerProvidesCA (default true). cert-manager only writes truststore.p12 when the issuer returns a ca.crt. For issuers that don't (ACME, for example), set it to false and the key store is used as the trust store too.
  • New arcadedb.tmpDirectory (default /tmp) for the ARCADEDB_PID and XDG_CACHE_HOME paths.

Other fixes

  • The Certificate's passwordSecretRef was hard-coded to arcadedb-credentials-secret. It now follows the same Secret as the pods.
  • The certificate SANs now include the -http and -external services, and HTTPS is exposed on the -http service as well.
  • ha.serverList declares its ports again (host:raftPort:httpPort, plus :0:httpsPort with TLS). Without them ArcadeDB guesses peer ports from its own and logs a warning on every start. The certificate uses a separate port-less helper for its DNS names.
  • The NetworkPolicy keeps its original <fullname>-http name so upgrades don't replace it.
  • The --- before the external Service is only emitted when that Service is rendered.

If any of this clashes with how you're deploying it, let me know and we can adjust.

@rlaveycal
rlaveycal deleted the tls branch October 6, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants