Skip to content

Conversation

@cmurphy
Copy link
Contributor

@cmurphy cmurphy commented Dec 13, 2025

Update tiles_tlog to accomodate minor differences in TesseraCT from rekor-tiles:

  • Add resources to manage secrets in Secret Manager instead of KMS
    • The private key secret version needs to be uploaded out of band
  • Make URL map paths configurable
    • When updating for rekor-tiles, operator needs to be aware that http_write_path, grpc_write_path, http_read_path, and http_read_rewrite_path need to be set to appropriate values for rekor-tiles
  • Rename some resources so they do not collide if rekor-tiles and TesseraCT happen to have the same shard name
  • Make gRPC load balancer routes optional

Relates to sigstore/rekor-tiles#73

Summary

Release Note

Documentation

@cmurphy cmurphy requested a review from a team as a code owner December 13, 2025 00:09
Update tiles_tlog to accomodate minor differences in TesseraCT from
rekor-tiles:

- Add resources to manage secrets in Secret Manager instead of KMS
  - The private key secret version needs to be uploaded out of band
- Make URL map paths configurable
  - When updating for rekor-tiles, operator needs to be aware that
    http_write_path, grpc_write_path, http_read_path, and
    http_read_rewrite_path need to be set to appropriate values for
    rekor-tiles
- Rename some resources so they do not collide if rekor-tiles and
  TesseraCT happen to have the same shard name
- Make gRPC load balancer routes optional

Signed-off-by: Colleen Murphy <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant