Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-78689

Update Init Container to Import Additional Certificates to OS CA-Certificates

XMLWordPrintable

    • 1
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Since the Amazon S3 CRT-based client currently utilizes the operating system's CA file instead of the Java truststore, this has presented challenges for customers, such as those running Jira on Kubernetes (k8s) and using the Amazon S3 CRT client with an on-premises S3-compatible storage solution. To address this, a workaround was implemented by using an additional init container and volume mounts to add certificates and execute the update-ca-certificates command.

      We propose enhancing the import certificate init container to automatically import additional certificates into the operating system's CA-certificates. This improvement would streamline the process for users and eliminate the need for manual workarounds, ensuring smoother integration and enhanced security for environments utilizing custom or additional CA certificates.

              Unassigned Unassigned
              97cfa19f8857 Ranjith Koolath
              Votes:
              2 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: