merge queue: checking #12659 on main (82fa6ed) - #12666
Closed
mergify[bot] wants to merge 2 commits into
Closed
Conversation
The enterprise docs never said how to make an on-premise deployment trust a private or self-signed certificate authority, and installation.mdx told operators to disable Redis TLS verification instead, which is the anti-pattern this was raised about. Add an enterprise page for MERGIFYENGINE_EXTRA_CA_BUNDLE: what belongs in the bundle, how to mount it, how to confirm it took effect, and the places where the setting alone is not enough. PostgreSQL needs sslmode=verify-full before libpq consults the roots at all, REDIS_SSL_VERIFY_MODE_CERT_NONE overrides the bundle, SSL_CERT_DIR reaches only part of the engine, and the bundle is read once per process so rotating the CA needs a restart. The PostgreSQL and Redis caveats come before the verification steps on purpose: a connectivity check against a connection that verifies nothing reports ok either way. installation.mdx now leads its self-signed Redis section with the bundle and keeps REDIS_SSL_VERIFY_MODE_CERT_NONE only as the fallback for a certificate you cannot obtain, while still telling a truly self-signed deployment to put the server certificate itself in the bundle, and pointing managed-Redis users at the CA their provider publishes. Its vague PostgreSQL "configure the connection options accordingly" becomes the concrete sslmode. The section heading is unchanged so its existing anchor keeps resolving. Troubleshooting and requirements link the page from the two places an operator hits the wall: a connectivity check that fails on certificate verification, and an egress proxy that re-signs the subscription calls. Fixes MRGFY-8831 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018XJzBXXpAFeRk3pLsADvjw Change-Id: Ib0ef33d61614b688512cfe24897e121790072193
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🎉 This pull request has been checked successfully and will be merged soon. 🎉
#12659 is queued for merge on branch main (82fa6ed).
This pull request has been created by Mergify to check the mergeability of #12659.
You don't need to do anything. Mergify will close this pull request automatically when it is complete.
Required conditions of queue rule
defaultfor merge:github-review-approved[🛡 GitHub repository ruleset ruleRequire pull request for default branch]schedule=Mon-Fri 09:00-17:30[Europe/Paris]Enforce conventional commit]:title ~= ^(fix|feat|internal|docs|style|refactor|perf|test|build|ci|chore|revert|ui)(?:\(.+\))?!?:👀 Review Requirements]:#approved-reviews-by >= 2author = dependabot[bot]author = renovate[bot]author = mergify-ci-bot-head ~= ^docs-agent/📕 PR description]:body ~= (?ms:.{48,})🔎 Reviews]:#changes-requested-reviews-by = 0#review-requested = 0#review-threads-unresolved = 0🤖 Continuous Integration]:check-success = buildcheck-success = lintcheck-success = testcheck-success = test-broken-linkslabel = ignore-broken-linkscheck-success=Cloudflare Pages-head-repo-full-name~=^Mergifyio/Required conditions to stay in the queue:
github-review-approved[🛡 GitHub repository ruleset ruleRequire pull request for default branch]Enforce conventional commit]:title ~= ^(fix|feat|internal|docs|style|refactor|perf|test|build|ci|chore|revert|ui)(?:\(.+\))?!?:👀 Review Requirements]:#approved-reviews-by >= 2author = dependabot[bot]author = renovate[bot]author = mergify-ci-bot-head ~= ^docs-agent/📕 PR description]:body ~= (?ms:.{48,})🔎 Reviews]:#changes-requested-reviews-by = 0#review-requested = 0#review-threads-unresolved = 0🤖 Continuous Integration]:check-success = buildcheck-success = lintcheck-success = testcheck-success = test-broken-linkslabel = ignore-broken-linkscheck-success=Cloudflare Pages-head-repo-full-name~=^Mergifyio/author != dependabot[bot]author != mergify-ci-botauthor != renovate[bot]head ~= ^docs-agent/