Skip to content

TLS-1.3 PQC embedded in the Operator - #1447

Open
desmax74 wants to merge 7 commits into
trustification:release/3.y.zfrom
desmax74:tls-configurator-merge
Open

desmax74 wants to merge 7 commits into
trustification:release/3.y.zfrom
desmax74:tls-configurator-merge

Conversation

@desmax74

@desmax74 desmax74 commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

TLS 1.3 Embedded in the Helm Chart Operator

Summary by Sourcery

Embed the TLS configurator in the operator and add optional runtime TLS reconciliation with TLS 1.3 post-quantum support.

New Features:

  • Embed the TLS configurator in the operator image with optional TLS 1.3 post-quantum cryptography support for Go workloads.
  • Add runtime TLS profile reconciliation that rolls configured workloads when the cluster-wide TLS configuration changes.
  • Provide TLS configuration inspection, validation, profile management, and OpenShift version-checking capabilities through the configurator CLI.

Enhancements:

  • Replace the one-shot TLS configuration hook Job with a long-running, RBAC-managed Deployment and configurable workload targets.
  • Add OpenShift TLS profile conversion, cipher-suite handling, PQC compliance checks, and rollout hashing support.
  • Expose Helm values and operator image wiring for enabling the configurator and PQC without a separate image.

Build:

  • Add standalone TLS configurator builds and package the binary alongside the operator manager.
  • Update project, chart, bundle, and release references to version 3.2.0.

CI:

  • Update Minikube end-to-end testing to use the 3.2.0 release candidate image.

Documentation:

  • Document the embedded TLS configurator, runtime reconciliation behavior, PQC configuration, image wiring, and required RBAC.

Tests:

  • Add unit and integration coverage for TLS profile validation, conversion, OpenShift version handling, controller behavior, and PQC compliance.

Chores:

  • Add OpenShift client dependencies and configure linting exceptions for TLS cipher-name tables.

@sourcery-ai

sourcery-ai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

This PR moves the TLS configurator into the operator repository and image, adds CLI/client/crypto support including optional TLS 1.3 PQC, and changes deployment from a Helm hook Job to a long-running, RBAC-backed reconciler that watches cluster TLS settings and rolls configured workloads at runtime.

Sequence diagram for runtime TLS reconciliation and rollout

sequenceDiagram
    participant APIServer as APIServer CR
    participant Reconciler as TLS Reconciler
    participant Deployment as Target Deployment
    participant Pods as Workload Pods

    Reconciler->>APIServer: WatchAPIServer
    APIServer-->>Reconciler: TLS profile change
    Reconciler->>APIServer: GetEffectiveTLSProfile
    Reconciler->>Deployment: GetDeploymentTLSHash
    alt hash differs
        Reconciler->>Deployment: SetDeploymentTLSHash
        Deployment-->>Pods: Rolling restart
    end
Loading

Flow diagram for PQC TLS configuration conversion

flowchart LR
    Profile[OpenShift TLSSecurityProfile]
    Convert[ConvertTLSProfileWithPQC]
    TLSConfig[crypto/tls.Config]
    PQC[EnablePQC]
    Groups[X25519MLKEM768 and X25519]

    Profile --> Convert
    Convert --> TLSConfig
    Convert --> PQC
    PQC --> TLSConfig
    PQC --> Groups
Loading

File-Level Changes

Change Details Files
Embed the TLS configurator as a second executable in the operator image and expose a standalone build target.
  • Build and install tls-configurator alongside manager in both operator image variants.
  • Add build-tls-configurator Make target and wire the binary into the Deployment through an explicit command.
  • Use the operator image digest for the configurator via RELATED_IMAGE_TLS_CONFIGURATOR, watches override values, and CSV related images.
Dockerfile
Dockerfile.rhtpa-operator.rh
Makefile
config/manager/manager.yaml
bundle/manifests/rhtpa-operator.clusterserviceversion.yaml
watches.yaml
Implement a complete TLS configurator CLI and supporting OpenShift clients for TLS profile management and validation.
  • Add CLI actions for reading, updating, listing, validating, and displaying effective TLS configuration.
  • Implement OpenShift APIServer, IngressController, ClusterVersion, and workload Deployment clients.
  • Add configuration loading, kubeconfig handling, profile validation/building, and OpenShift version checks.
cmd/tls-configurator/main.go
pkg/tlsconfigurator/client/apiserver.go
pkg/tlsconfigurator/client/client.go
pkg/tlsconfigurator/client/version.go
pkg/tlsconfigurator/client/workloads.go
pkg/tlsconfigurator/config/config.go
pkg/tlsconfigurator/controller/controller.go
Add TLS profile conversion to Go crypto/tls configuration with optional TLS 1.3 post-quantum key exchange.
  • Convert OpenShift profile types, protocol versions, and OpenSSL/IANA cipher names into Go TLS settings.
  • Add PQC support using X25519MLKEM768 with X25519 fallback, TLS 1.3 enforcement, and compliance reporting.
  • Cover modern, intermediate, old, custom, cipher conversion, and PQC behavior with unit tests.
pkg/tlsconfigurator/crypto/crypto.go
pkg/tlsconfigurator/crypto/crypto_test.go
pkg/tlsconfigurator/crypto/pqc_test.go
Replace the one-shot Helm hook Job with a persistent runtime TLS reconciler Deployment.
  • Watch the cluster APIServer TLS profile and perform an initial plus periodic reconciliation.
  • Hash the effective TLS profile and PQC setting, then patch target Deployment pod-template annotations to trigger rolling updates only when needed.
  • Add configurable target namespace, target Deployments, resync period, and PQC enablement.
pkg/tlsconfigurator/reconcile/reconcile.go
helm-charts/redhat-trusted-profile-analyzer/templates/init/tls-configure/010-ServiceAccount.yaml
helm-charts/redhat-trusted-profile-analyzer/templates/init/tls-configure/015-ClusterRole.yaml
helm-charts/redhat-trusted-profile-analyzer/templates/init/tls-configure/016-Role.yaml
helm-charts/redhat-trusted-profile-analyzer/templates/init/tls-configure/017-RoleBinding.yaml
helm-charts/redhat-trusted-profile-analyzer/templates/init/tls-configure/018-ClusterRoleBinding.yaml
helm-charts/redhat-trusted-profile-analyzer/templates/init/tls-configure/020-Deployment.yaml
helm-charts/redhat-trusted-profile-analyzer/values.yaml
helm-charts/redhat-trusted-profile-analyzer/values.schema.yaml
helm-charts/redhat-trusted-profile-analyzer/values.schema.json
Add RBAC, dependency, lint, documentation, and test coverage for the embedded configurator.
  • Grant the operator permissions required to create and manage the configurator's persistent resources and workload rollouts.
  • Add OpenShift API/client, Ginkgo/Gomega, and related module dependencies.
  • Document deployment wiring, runtime reconciliation, PQC scope, configuration, RBAC, and the known duplicate static-bundle RBAC issue.
  • Add unit and Ginkgo integration-style coverage for configuration, validation, comparison, conversion, and edge cases.
config/rbac/kustomization.yaml
config/rbac/role_cluster_rbac_manager.yaml
config/rbac/role_cluster_rbac_manager_binding.yaml
config/rbac/role_cluster_tlsconfigurator.yaml
config/rbac/role_binding_tlsconfigurator.yaml
config/rbac/service_account.yaml
go.mod
go.sum
test/tlsconfigurator/suite_test.go
.golangci.yml
CLAUDE.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="pkg/tlsconfigurator/reconcile/reconcile.go" line_range="183-200" />
<code_context>
+	return nil
+}
+
+// TLSConfigHash returns a stable hash of the effective TLS configuration. The
+// PQC flag is part of the hash so that toggling post-quantum forces a rollout.
+func TLSConfigHash(profile *configv1.TLSSecurityProfile, enablePQC bool) (string, error) {
+	payload := struct {
+		Profile *configv1.TLSSecurityProfile `json:"profile"`
+		PQC     bool                         `json:"pqc"`
+	}{
+		Profile: profile,
+		PQC:     enablePQC,
+	}
+
+	data, err := json.Marshal(payload)
+	if err != nil {
+		return "", fmt.Errorf("failed to marshal TLS config for hashing: %w", err)
+	}
+
+	sum := sha256.Sum256(data)
+	return fmt.Sprintf("%x", sum), nil
+}
+
</code_context>
<issue_to_address>
**nitpick (bug_risk):** `TLSConfigHash` hashes the raw profile object rather than the effective TLS configuration described by the function comment, so an unset cluster profile and an explicitly configured equivalent Intermediate profile produce different hashes and trigger an unnecessary rolling restart.

**Triggers:** When the cluster changes between an omitted TLS profile and an explicit Intermediate profile with equivalent effective settings.

**Suggested fix:** Resolve the default profile and hash the converted effective TLS configuration, including the PQC setting, rather than hashing the raw API object.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. When enabled, the reconciler changes TLS-related workload behavior, cluster RBAC, and rolling restarts, while the one-shot update path can persist TLS policy changes that a code revert would not restore. A faulty TLS or permission decision could expose traffic or grant unintended cluster access, and any rollout outage or policy change would already have occurred before reverting.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread pkg/tlsconfigurator/reconcile/reconcile.go
@desmax74 desmax74 changed the title TLS-1.3 embedded on Operator TLS-1.3 PQC embedded in the Operator Sep 25, 2026
desmax74 and others added 2 commits September 25, 2026 16:41
Signed-off-by: desmax74 <mdessi@redhat.com>
Signed-off-by: Max Dessi <mdessi@mdessi-thinkpadp1gen8.rmtit.csb>
@desmax74
desmax74 force-pushed the tls-configurator-merge branch from 6137cd4 to 5b695e8 Compare September 25, 2026 14:41
Max Dessi and others added 5 commits September 25, 2026 16:57
Signed-off-by: Max Dessi <mdessi@mdessi-thinkpadp1gen8.rmtit.csb>
Signed-off-by: Max Dessi <mdessi@mdessi-thinkpadp1gen8.rmtit.csb>
Signed-off-by: Max Dessi <mdessi@mdessi-thinkpadp1gen8.rmtit.csb>
@desmax74

Copy link
Copy Markdown
Collaborator Author

@sourcery-ai

@sourcery-ai

sourcery-ai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

I’m here—please share the specific question or follow-up you’d like me to address about the review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant