Add CA Bundle support for user-code runtimes - #91
Merged
Merged
Conversation
Jeff McCollum (jeffmccollum)
requested review from
brianvans (brianvans) and
Erik Weathers (erikdw)
July 30, 2026 16:22
| - name: TS_API_HEALTHSERVER_PORT | ||
| value: {{ .Values.api.healthServer.port | quote }} | ||
| {{- if .Values.api.customCA.enabled }} | ||
| {{- $customCAPath := printf "%s/%s" (required "api.customCA.mountPath is required when api.customCA.enabled is true" .Values.api.customCA.mountPath) (required "api.customCA.filename is required when api.customCA.enabled is true" .Values.api.customCA.filename) }} |
Contributor
There was a problem hiding this comment.
nit - could we consolidate all the requireds for CA stuff into a central place in this file to clean things up bit?
brianvans (brianvans)
previously approved these changes
Jul 30, 2026
brianvans (brianvans)
left a comment
Contributor
There was a problem hiding this comment.
Looks good! Left two nits but not blocking
Updated terminology for clarity regarding CA bundle.
Co-authored-by: Cursor <cursoragent@cursor.com>
brianvans (brianvans)
approved these changes
Jul 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR in combination with v2.9.0 of the Data Plane, supports adding a CA bundle of certificates to the API pod. This solution is only for user-defined/code function execution when it needs to talk to an endpoint that uses a private or enterprise CAs where otherwise it would have an untrusted certificate.