Repository navigation
test(tmachine): add K3s PostgreSQL and mTLS conformance installer - #4081
Draft
matthewgrossman wants to merge 3 commits into
Draft
matthewgrossman wants to merge 3 commits into
matthewgrossman wants to merge 3 commits into
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Drop the port-forward restart removed by the ClusterIP change, resolve the Service DNS name covered by the server certificate to the ClusterIP, bound each authenticated API wait attempt, and collect diagnostics from every gateway Pod. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
matthewgrossman
force-pushed
the
3529-tmachine-k3s-postgres-mtls/mg
branch
from
October 9, 2026 20:34
b6bd150 to
e772f89
Compare
Add the k3s-ha-tls installer to every core conformance matrix so Branch E2E, Release Dev, Release Tag, and manual Integration Tests cover three gateway replicas sharing PostgreSQL behind mTLS. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-4081.docs.buildwithfern.com/openshell |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add a
k3s-ha-tlstmachine installer: three K3s gateway replicas sharing PostgreSQL, chart-generated TLS, and a guest CLI registered with mTLS. It runs the existing conformance archive and provides the deployment prerequisite for migrating #3825's HA scenarios.Related Issue
Refs #3529 (deployment prerequisite only).
Changes
allowUnauthenticatedUsersfor its application-level development user.openshell.openshell.svc.cluster.localbut not the ClusterIP, so the installer maps that name to the ClusterIP in the guest's/etc/hostsand registershttps://openshell.openshell.svc.cluster.local:<port>.openshell-0, so the Deployment-based HA install is covered.k3s-ha-tlsto the core conformance matrix in Branch E2E, Release Dev, Release Tag, and the Integration Tests defaults, and note the lane inCI.md.nix run .#tmachine -- test ubuntu-k3s k3s-ha-tls conformanceTesting
mise run pre-commit.61d42102cimages.387026536, including the newk3s-ha-tlsconformance lane alongside baselinek3s.Checklist