Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Wolfi Package Request]: AWS RDS CA Bundles #16479

Open
3 of 4 tasks
lyoung-confluent opened this issue Apr 8, 2024 · 2 comments · May be fixed by #23836
Open
3 of 4 tasks

[Wolfi Package Request]: AWS RDS CA Bundles #16479

lyoung-confluent opened this issue Apr 8, 2024 · 2 comments · May be fixed by #23836
Labels
needs-triage applied to all new customer/user issues. Removed after triage occurs. wolfi-package-request used to track requests for new wolfi packages

Comments

@lyoung-confluent
Copy link
Contributor

lyoung-confluent commented Apr 8, 2024

What software would you like us to add to wolfi-os. Ideally include a URL to the project and its source.

https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html

which versions of the software should we include?

latest?

Add some justification for why this specific package and versions are important.

When connecting to AWS RDS DB using TLS, the instances do not use a public Certificate Authority that would be part of the standard ca-certificates-bundle. Instead there are per-region certificate bundles made available by AWS.

It would be useful to have something like an aws-rds-certificates package that includes these bundles so it's easy for applications that connect to an RDS DB to do so securely (i.e. sslmode=verifyfull). We could follow a similar model as glibc using a data element to build each region as an separate package so only the regions a service needs can be installed.

One complexity here is that while AWS hosts these certificates for easy download, they do not appear to be versioned. Maybe we can just use the checksum feature of fetch to ensure they are not changed unexpectedly?

Please check all that apply

  • This package has an un-restrictive license
  • The package/versions proposed are actively maintained upstream
  • I am interested in adding this package to Wolfi OS myself
  • I am willing to help maintain this package
@lyoung-confluent lyoung-confluent added needs-triage applied to all new customer/user issues. Removed after triage occurs. wolfi-package-request used to track requests for new wolfi packages labels Apr 8, 2024
@tuananh
Copy link
Contributor

tuananh commented Jul 11, 2024

@lyoung-confluent is this still needed?

@lyoung-confluent
Copy link
Contributor Author

@tuananh Yes, I still think it would be a useful package

@tuananh tuananh linked a pull request Jul 11, 2024 that will close this issue
15 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs-triage applied to all new customer/user issues. Removed after triage occurs. wolfi-package-request used to track requests for new wolfi packages
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants