Interested in a PR for mTLS #209
Replies: 1 comment 1 reply
Not interested |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Application
Shlink
Application version
v5.1.5
How do you serve the application
K8s
Database engine (if any)
MariaDB
Database version
11.8.8
Summary
I'm running Shlink in a Kubernetes cluster where the database enforces mutual TLS — every client must present a certificate, not just trust the server's. Shlink's
DB_USE_ENCRYPTIONcurrently only does one-way TLS (and trusts any server cert), so there's no way to present a client cert for thepdo_mysql/pdo_pgsqlconnection.I'm working on a patch that adds
DB_CLIENT_CERT_PATH,DB_CLIENT_KEY_PATH, andDB_CA_CERT_PATHenv vars, wired into the existingdriverOptionsinconfig/autoload/entity-manager.global.php(settingPdo\Mysql::ATTR_SSL_CERT/ATTR_SSL_KEY/ATTR_SSL_CA, plus turning onATTR_SSL_VERIFY_SERVER_CERTwhen a CA is supplied). Using Claude Code to help draft it, but I'll test and review everything myself before opening anything.Would this be a welcome PR, or is there a reason mTLS-style DB auth hasn't been added already? Also open to different env var names if you have a preferred convention.
All reactions