Skip to content

merge queue: checking #12658 on main (82fa6ed), stacked on #12659 - #12667

Closed
mergify[bot] wants to merge 4 commits into
mainfrom
mergify/merge-queue/817e955a56
Closed

merge queue: checking #12658 on main (82fa6ed), stacked on #12659#12667
mergify[bot] wants to merge 4 commits into
mainfrom
mergify/merge-queue/817e955a56

Conversation

@mergify

@mergify mergify Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request has been checked successfully and will be merged soon. 🎉

#12658 is queued for merge on branch main (82fa6ed).

Stacked behind 1 pull request queued ahead of this batch, not part of it. These checks run on a tip that also carries its commits, so a failure here can come from it as much as from #12658.

Queued ahead of this batch:

This pull request has been created by Mergify to speculatively check the mergeability of #12658.
You don't need to do anything. Mergify will close this pull request automatically when it is complete.

Required conditions of queue rule default for merge:

Required conditions to stay in the queue:

---
checking_base_sha: 28f8d2b99a77303165a9d6cd10a6d31275a7440c
previous_check_retries: []
previous_failed_batches: []
pull_requests:
  - number: 12658
    scopes: []
scopes: []
...

sileht and others added 4 commits September 2, 2026 15:32
The enterprise docs never said how to make an on-premise deployment trust a
private or self-signed certificate authority, and installation.mdx told
operators to disable Redis TLS verification instead, which is the anti-pattern
this was raised about.

Add an enterprise page for MERGIFYENGINE_EXTRA_CA_BUNDLE: what belongs in the
bundle, how to mount it, how to confirm it took effect, and the places where
the setting alone is not enough. PostgreSQL needs sslmode=verify-full before
libpq consults the roots at all, REDIS_SSL_VERIFY_MODE_CERT_NONE overrides the
bundle, SSL_CERT_DIR reaches only part of the engine, and the bundle is read
once per process so rotating the CA needs a restart. The PostgreSQL and Redis
caveats come before the verification steps on purpose: a connectivity check
against a connection that verifies nothing reports ok either way.

installation.mdx now leads its self-signed Redis section with the bundle and
keeps REDIS_SSL_VERIFY_MODE_CERT_NONE only as the fallback for a certificate
you cannot obtain, while still telling a truly self-signed deployment to put
the server certificate itself in the bundle, and pointing managed-Redis users
at the CA their provider publishes. Its vague PostgreSQL "configure the
connection options accordingly" becomes the concrete sslmode. The section
heading is unchanged so its existing anchor keeps resolving.

Troubleshooting and requirements link the page from the two places an operator
hits the wall: a connectivity check that fails on certificate verification, and
an egress proxy that re-signs the subscription calls.

Fixes MRGFY-8831

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018XJzBXXpAFeRk3pLsADvjw
Change-Id: Ib0ef33d61614b688512cfe24897e121790072193
@mergify
mergify Bot deployed to Mergify Merge Protections September 3, 2026 07:43 Active
@mergify mergify Bot closed this Sep 3, 2026
@mergify
mergify Bot deleted the mergify/merge-queue/817e955a56 branch September 3, 2026 07:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants