[09:05:10] Hello all. I have another small change to `profile::kubernetes::master` that I would like to share for review, please. https://gerrit.wikimedia.org/r/c/operations/puppet/+/1347693 [09:05:10] No-op for all clusters, then enabled for dse-k8s-codfw by the next patch in the stack. Backstory in T439865. Thanks. [09:05:11] T439865: Sign dse-k8s service-account tokens with RSA keys, so that the RADOS Gateway can verify them - https://phabricator.wikimedia.org/T439865 [12:06:04] btullis: o/ it seems good afaics but I'd wait for jayme or jelto to double check, for awareness. One thing that I didn't get - when you mention that the new cert will be stored in etcd, what do you mean exactly? As in, serialized as normal resource etc.. or something different? [12:06:23] namely, how will it be provisioned? [12:22:25] Thanks elukey - Yes I'm certainly not going to muck about with SA signing keys on a Friday. Happy to wait for more reviews. [12:22:25] The publishing part comes from here: https://github.com/wikimedia/operations-puppet/blob/production/modules/profile/manifests/kubernetes/master.pp#L97-L110 [12:23:04] ah ok TIL I didn't know that bit [12:25:00] My patch doesn't change anything about the way it is provisioned, other than by changing the algorithm. At least, that's the theory. [12:25:05] https://www.irccloud.com/pastebin/Vn0m2lsj/ [12:26:27] ok so it switches ecdsa with rsa, okok [12:26:34] <_joe_> Integrating through etcd and not the k8s api is kind of questionable; I get why you did it but "integration via the database" will always be the bearer of issues long-term [12:27:04] <_joe_> I don't think sadly there's anything doing confd's work with the k8s api :( [12:35:50] _joe_: Yes, but that's not the problem that I'm trying to solve today. That publishing the sa signing certs via etcd was added in November 2024. What I'm working on is getting the Ceph Rados Gateway to be able to validate JWTs signed by the k8s API.