Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Today we have three copies of Certificate synthesis across:
This has burned us several times in recent memory (off the top of my head):
By having a largely common code path for these, we should be able to avoid some of these breaks.
This change creates a method in x509ca to make an
x509.Certificate
and then reorients the bulk of the redundant certificate construction into translation logic from the shared construction.Signed-off-by: Matt Moore mattmoor@chainguard.dev
Release Note