mirror of
https://github.com/tailscale/tailscale.git
synced 2025-07-31 16:23:44 +00:00
code review feedback
Signed-off-by: Irbe Krumina <irbe@tailscale.com>
This commit is contained in:
parent
4eec19eb3f
commit
bcff106b4b
@ -146,7 +146,7 @@ func (b *LocalBackend) GetCertPEMWithValidity(ctx context.Context, domain string
|
|||||||
}
|
}
|
||||||
|
|
||||||
if envknob.IsCertShareReadOnlyMode() {
|
if envknob.IsCertShareReadOnlyMode() {
|
||||||
return nil, fmt.Errorf("retrieving cached TLS credentials failed with %w, and cert store is configured in read-only mode, not attempting to issue new credentials", err)
|
return nil, fmt.Errorf("retrieving cached TLS certificate failed with %w, and cert store is configured in read-only mode, not attempting to issue new certificate", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
pair, err := getCertPEM(ctx, b, cs, logf, traceACME, domain, now, minValidity)
|
pair, err := getCertPEM(ctx, b, cs, logf, traceACME, domain, now, minValidity)
|
||||||
@ -365,11 +365,18 @@ type certStateStore struct {
|
|||||||
testRoots *x509.CertPool
|
testRoots *x509.CertPool
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TLSCertKeyReader is an interface implemented by state stores where it makes
|
||||||
|
// sense to read the TLS cert and key in a single operation that can be
|
||||||
|
// distinguished from generic state value reads. Currently this is only implemented
|
||||||
|
// by the kubestore.Store, which, in some cases, need to read cert and key from a
|
||||||
|
// non-cached TLS Secret.
|
||||||
|
type TLSCertKeyReader interface {
|
||||||
|
ReadTLSCertAndKey(domain string) ([]byte, []byte, error)
|
||||||
|
}
|
||||||
|
|
||||||
func (s certStateStore) Read(domain string, now time.Time) (*TLSCertKeyPair, error) {
|
func (s certStateStore) Read(domain string, now time.Time) (*TLSCertKeyPair, error) {
|
||||||
// If we're using a store that supports atomic reads, use that
|
// If we're using a store that supports atomic reads, use that
|
||||||
if kr, ok := s.StateStore.(interface {
|
if kr, ok := s.StateStore.(TLSCertKeyReader); ok {
|
||||||
ReadTLSCertAndKey(string) ([]byte, []byte, error)
|
|
||||||
}); ok {
|
|
||||||
cert, key, err := kr.ReadTLSCertAndKey(domain)
|
cert, key, err := kr.ReadTLSCertAndKey(domain)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
Loading…
x
Reference in New Issue
Block a user