Skip to content

Add: separate TLS certificates for ingress server and agent control - #43

Merged
pascalholthaus merged 5 commits into
mainfrom
pholthaus/ingress-agent
Oct 5, 2026
Merged

pascalholthaus merged 5 commits into
mainfrom
pholthaus/ingress-agent

Conversation

@pascalholthaus

@pascalholthaus pascalholthaus commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What

Add: Separate TLS certificates for ingress server and agent control

Why

CPB-993

References

CPB-993

Checklist

  • I have used the following LLMs/AI tools in this pull request:
  • Doc strings by chatgpt
  • Review copilot

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Existing deployments may fail without a migration path, and the documented EC key requirement is not enforced.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds separate TLS certificate handling for the ingress server and agent-control endpoint.

Changes:

  • Adds agent-control certificate options and configuration.
  • Generates and loads separate certificate pairs.
  • Updates CLI help and README documentation.
File Summary
src/​help.sh Documents certificate options; EC key requirement conflicts with current validation.
src/​global.sh Adds agent-control certificate variables.
src/​certs.sh Implements separate certificate handling; requires backward compatibility and EC key validation.
src/​args.sh Parses agent-control certificate arguments.
README.md Documents the new certificate configuration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/certs.sh Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Resolve deployment-mode validation and EC key-type validation issues.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
Resolved since last review (1)

Comment thread src/args.sh
Comment thread src/certs_agent.sh
@pascalholthaus
pascalholthaus marked this pull request as ready for review October 5, 2026 08:56
@pascalholthaus
pascalholthaus requested a review from a team as a code owner October 5, 2026 08:56
@greenbonebot
greenbonebot enabled auto-merge (squash) October 5, 2026 09:01
@pascalholthaus
pascalholthaus force-pushed the pholthaus/ingress-agent branch from 37c3476 to 0de783a Compare October 5, 2026 09:07
@pascalholthaus
pascalholthaus enabled auto-merge (squash) October 5, 2026 09:33
@pascalholthaus
pascalholthaus merged commit eca6198 into main Oct 5, 2026
11 checks passed
@pascalholthaus
pascalholthaus deleted the pholthaus/ingress-agent branch October 5, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants