Skip to content

Update the default CA bundle more frequently #666

@bodgit

Description

@bodgit

We are using trust-manager with the useDefaultCAs option however I found that I was missing a fairly new CA, (O = Sectigo Limited), that wasn't present.

Peeking around in the quay.io repository the 20230311.0 tag was published ~6 months ago. I found there was a 20230311-deb12u1.0 tag that was newer and switching to using that tag fixed the missing cert for me.

Would it be possible to get this image updated more frequently?Ideally you would only publish a new tag if the CA certs are different to the previous tag. We could then use something like Renovate to update the tag value in the Helm chart if/when a newer tag is available.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions