Commit 98e8503
fix(llm-request-router): validate certificate SANs against the PKI role
The OpenBao signing role this chart provisions is created with
allow_subdomains=true and allow_bare_domains=false. A certificate SAN outside
pki.allowedDomains therefore renders cleanly and is then rejected by OpenBao at
issuance, surfacing as a cert-manager failure with no pointer back to the value
that caused it. This was the one coupling in the LLM PKI path with no
render-time guard.
Enabling backend routing with the LLM addon made it materially easier to hit.
The chart appends the pod-hostname wildcard to the Certificate whenever backend
routing is on, so every LLM deployment with PKI now requests an in-cluster
wildcard. An operator whose allowedDomains omits cluster.local previously
rendered and installed; now the request would be refused at issuance.
Validate coverage at render instead, applying the role's own rules: a name is
covered when it is a strict subdomain of an allowed domain, a wildcard is
additionally covered when it sits directly on one, and a bare domain is never
covered because the role refuses bare issuance.
The tests pin the cases that must NOT fail as well as those that must. A guard
that is too strict here would block valid deployments, which is worse than the
trap it replaces. Three of them were initially passing for the wrong reason and
were corrected: the near-miss suffix case had the pattern inverted, and the
bare-domain case was failing on the appended wildcard rather than on the bare
name, so the bare rule was never exercised.
Relates to #689
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Mike Camp <mcamp@nvidia.com>1 parent f5953ad commit 98e8503
3 files changed
Lines changed: 108 additions & 0 deletions
File tree
- deploy/helm/llm-request-router
- llm-request-router/templates
- scripts
Lines changed: 42 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
174 | 174 | | |
175 | 175 | | |
176 | 176 | | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
177 | 219 | | |
178 | 220 | | |
179 | 221 | | |
| |||
Lines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| |||
Lines changed: 65 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
430 | 430 | | |
431 | 431 | | |
432 | 432 | | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
433 | 498 | | |
0 commit comments