Skip to content

PBM-1695: Document multiple storage TLS certificates - #409

Merged
rasika-chivate merged 4 commits into
mainfrom
PBM-1695-multiple-storage-tls-certificates
Oct 6, 2026
Merged

rasika-chivate merged 4 commits into
mainfrom
PBM-1695-multiple-storage-tls-certificates

Conversation

@rasika-chivate

Copy link
Copy Markdown
Collaborator

Documents certificate trust for multiple custom storage services in the PBM 2.17.0 docs. Users can point SSL_CERT_DIR to a directory of PEM certificate files or use SSL_CERT_FILE with a certificate bundle. The instructions cover each host running the agent or CLI, system root certificates, and configuring the environment of a systemd-managed agent.

This documents existing behavior confirmed in the ticket. It does not claim that support first appeared in 2.17.0. Jira has no fix version set, and no implementation PR was found or linked.

Changed files and placement

  • docs/details/minio.md: updates Data upload to storage with self-signed TLS certificates → Usage example.
  • docs/details/s3-storage.md: updates the matching section to keep both storage guides consistent.

Preserves existing section anchors, navigation and TLS warnings. Both pages already appear in mkdocs-base.yml; no new page or section is needed. Links to storage profiles, agent environment configuration, PBM logs and upstream Go certificate loading.

Claim-to-source map

Claim Source
Directory and bundled-file approaches both work PBM-1695, Oleksandr's confirmation
SSL_CERT_DIR example; configure hosts running agent and CLI; system roots when neither variable is set PBM-1695, Jakub's instructions
Use case: profiles with different storage certificates PBM-1695 description
Certificate file and directory environment variables Go SystemCertPool
systemd-managed agent uses an environment file Existing docs/install/configure-authentication.md, Set the MongoDB connection URI for pbm-agent, including the EnvironmentFile unit setting and platform-specific paths
Agent restart Existing docs/install/secure-credentials-systemd.md, sudo systemctl restart pbm-agent; fixes the prior example that said restart but ran start
Paths in examples Illustrative paths based on the existing /etc/ssl/minio-ca.crt example and the ticket's directory approach; not fixed product defaults

Validation

MkDocs build and git diff --check passed. Verified both rendered page TOCs, numbered steps, code blocks, existing TLS warnings and new internal links. Existing unrelated link warnings remain. Examples were reviewed against the sources; no live deployments were changed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation is consistent, technically sound, and preserves valid links and warnings.

Review effort: Balanced
Findings: None

What changed in this PR

Documents how PBM trusts certificates for multiple custom storage services.

Changes:

  • Documents SSL_CERT_FILE bundles and SSL_CERT_DIR.
  • Adds shell and systemd configuration steps.
  • Corrects the agent restart command.
File Description
docs/​details/​minio.md Updates MinIO certificate trust guidance.
docs/​details/​s3-storage.md Updates S3-compatible storage certificate guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@nastena1606
nastena1606 temporarily deployed to PBM-1695-multiple-storage-tls-certificates - pbm-docs-preview PR #409 October 6, 2026 08:14 — with Render Destroyed
@rasika-chivate
rasika-chivate marked this pull request as ready for review October 6, 2026 08:15
@rasika-chivate
rasika-chivate requested review from boris-ilijic and olexandr-havryliak and a balanced review from Copilot October 6, 2026 08:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation is consistent, accurate, and includes valid references and operational steps.

Review effort: Balanced
Findings: None

@rasika-chivate
rasika-chivate merged commit a3fd106 into main Oct 6, 2026
1 check passed

This branch was successfully deployed

No deployments
PBM-1695-multiple-storage-tls-certificates - pbm-docs-preview PR #409 — 0f310448 Deployed Oct 6, 2026 by nastena1606
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants