Skip to content

[DPE-8698] 4.x Config to switch cluster to DNS#436

Draft
zmraul wants to merge 4 commits intomainfrom
feat/4/dpe-8698-dns-certs
Draft

[DPE-8698] 4.x Config to switch cluster to DNS#436
zmraul wants to merge 4 commits intomainfrom
feat/4/dpe-8698-dns-certs

Conversation

@zmraul
Copy link
Contributor

@zmraul zmraul commented Nov 19, 2025

Solves #424 for 4 track

Introduces a new boolean config option certificate_include_ip_sans that defaults to false. This config also forces the cluster to switch to dns based hostnames (otherwise remote apps won't be able to verify Kafka certificates when TLS is enabled)

TODO

  • : Remaining issue with TLS is due to setup_internal_tls flow. When IPs are disabled from the cluster via config, the internal tls setup that uses IP based certificates becomes obsolete. The nodes fail to verify the internal certificates.

@zmraul zmraul changed the title [DPE-8698] Add ip sans include config option [DPE-8698] 4.x Add ip sans include config option Nov 20, 2025
@zmraul zmraul changed the title [DPE-8698] 4.x Add ip sans include config option [DPE-8698] 4.x Config to switch cluster to DNS Nov 20, 2025
zmraul and others added 2 commits December 12, 2025 12:40
Signed-off-by: Raúl Zamora Martínez <76525382+zmraul@users.noreply.github.com>
@zmraul zmraul requested review from imanenami and marcoppenheimer and removed request for marcoppenheimer December 12, 2025 11:46
@zmraul zmraul marked this pull request as ready for review December 12, 2025 11:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant