Skip to content

merge queue: checking #12659 on main (82fa6ed) - #12666

Closed
mergify[bot] wants to merge 2 commits into
mainfrom
mergify/merge-queue/4bb4ef627d
Closed

merge queue: checking #12659 on main (82fa6ed)#12666
mergify[bot] wants to merge 2 commits into
mainfrom
mergify/merge-queue/4bb4ef627d

Conversation

@mergify

@mergify mergify Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request has been checked successfully and will be merged soon. 🎉

#12659 is queued for merge on branch main (82fa6ed).

This pull request has been created by Mergify to check the mergeability of #12659.
You don't need to do anything. Mergify will close this pull request automatically when it is complete.

Required conditions of queue rule default for merge:

Required conditions to stay in the queue:

---
checking_base_sha: 82fa6edb480d2c84242406430282d2b159c499d9
previous_check_retries: []
previous_failed_batches: []
pull_requests:
  - number: 12659
    scopes: []
scopes: []
...

sileht and others added 2 commits September 2, 2026 15:32
The enterprise docs never said how to make an on-premise deployment trust a
private or self-signed certificate authority, and installation.mdx told
operators to disable Redis TLS verification instead, which is the anti-pattern
this was raised about.

Add an enterprise page for MERGIFYENGINE_EXTRA_CA_BUNDLE: what belongs in the
bundle, how to mount it, how to confirm it took effect, and the places where
the setting alone is not enough. PostgreSQL needs sslmode=verify-full before
libpq consults the roots at all, REDIS_SSL_VERIFY_MODE_CERT_NONE overrides the
bundle, SSL_CERT_DIR reaches only part of the engine, and the bundle is read
once per process so rotating the CA needs a restart. The PostgreSQL and Redis
caveats come before the verification steps on purpose: a connectivity check
against a connection that verifies nothing reports ok either way.

installation.mdx now leads its self-signed Redis section with the bundle and
keeps REDIS_SSL_VERIFY_MODE_CERT_NONE only as the fallback for a certificate
you cannot obtain, while still telling a truly self-signed deployment to put
the server certificate itself in the bundle, and pointing managed-Redis users
at the CA their provider publishes. Its vague PostgreSQL "configure the
connection options accordingly" becomes the concrete sslmode. The section
heading is unchanged so its existing anchor keeps resolving.

Troubleshooting and requirements link the page from the two places an operator
hits the wall: a connectivity check that fails on certificate verification, and
an egress proxy that re-signs the subscription calls.

Fixes MRGFY-8831

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018XJzBXXpAFeRk3pLsADvjw
Change-Id: Ib0ef33d61614b688512cfe24897e121790072193
@mergify
mergify Bot deployed to Mergify Merge Protections September 3, 2026 07:42 Active
@mergify mergify Bot closed this Sep 3, 2026
@mergify
mergify Bot deleted the mergify/merge-queue/4bb4ef627d branch September 3, 2026 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant