Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Custom CA - GA or Deprecated? #4596

Open
TimJongerius opened this issue Oct 22, 2024 · 3 comments
Open

[Question] Custom CA - GA or Deprecated? #4596

TimJongerius opened this issue Oct 22, 2024 · 3 comments
Labels

Comments

@TimJongerius
Copy link

We are currently leveraging the AKS Custom CA (Preview) feature to connect our AKS clusters with private, on-premise container registries (e.g., Nexus), which require custom Certificate Authorities (CAs). This is a crucial part of our setup, as we need to pull images from these private registries for compliance and security reasons.

Given that this feature has been in Preview for a significant period, we are concerned about its future, as we’ve heard rumors regarding its potential deprecation. The uncertainty around this is troubling, as many of our clients depend on this functionality for their production workloads.

Could you provide an update on the current state of the AKS Custom CA feature? Specifically:

What is the plan for this feature? Are there any timelines for it to reach General Availability (GA)?
What challenges are preventing it from moving out of Preview?
If deprecation is being considered, what alternatives should we explore to maintain the ability to connect AKS to private on-premise registries with custom CAs?

Our clients are eagerly waiting for a stable, supported solution, and any clarity you can provide would be greatly appreciated.

Best regards
Tim Jongerius

@jkroepke
Copy link

Our clients are eagerly waiting for a stable, supported solution, and any clarity you can provide would be greatly appreciated.

Issue public certificates even for private endpoint is that best possible option that you can today.

@TimJongerius
Copy link
Author

Our clients are eagerly waiting for a stable, supported solution, and any clarity you can provide would be greatly appreciated.

Issue public certificates even for private endpoint is that best possible option that you can today.

Sadly that is not under our control so we have to live with what is given to us.

@UtheMan
Copy link

UtheMan commented Oct 24, 2024

Hi @TimJongerius , the work required for GA is currently ongoing. While we are still exploring different options for our final GA design, the feature will be brought to GA. There is no definitive ETA to share right now, but we are targeting Q1 2025 at this time.

Potential changes that are being considered is removal of the "after node creation" flow, only keeping the "before node boots up" way.

If you have any comments/thoughts on how the feature works today - please feel free to share here. Feedback is always welcome and very helpful as we finalize the design.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants