Skip to content

Conversation

@gwossum
Copy link
Member

@gwossum gwossum commented Dec 23, 2025

Add TLS certificate reloading on SIGHUP. For httpd service certificates, the configuration is reloaded and certificate and key file locations are updated accordingly. For opentsdb service certificates, certificates and keys at the existing locations are reloaded. If reloading a certificate fails, the currently loaded certificate continues to be used.

Also adds file permission checking for TLS certificates and private keys.

Clean cherry-pick of #26994 to 1.12.

Closes: #27056

(cherry picked from commit 8c9b850)

Add TLS certificate reloading on SIGHUP. For httpd service certificates,
the configuration is reloaded and certificate and key file locations are
updated accordingly. For opentsdb service certificates, certificates and
keys at the existing locations are reloaded. If reloading a certificate
fails, the currently loaded certificate continues to be used.

Also adds file permission checking for TLS certificates and private
keys.

Clean cherry-pick of #26994 to 1.12.

Closes: #27056

(cherry picked from commit 8c9b850)
@gwossum gwossum self-assigned this Dec 23, 2025
@gwossum gwossum marked this pull request as ready for review December 23, 2025 21:14
Copy link
Contributor

@davidby-influx davidby-influx left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@gwossum gwossum merged commit aa1775b into 1.12 Dec 23, 2025
9 checks passed
@gwossum gwossum deleted the gw/27056/tls_cert_omnibux_1.12 branch December 23, 2025 21:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants