paddyabc opened a new issue, #17550:
URL: https://github.com/apache/dolphinscheduler/issues/17550

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/dolphinscheduler/issues?q=is%3Aissue) and 
found no similar feature requirement.
   
   
   ### Description
   
   In the normal production deployment, we will have a database which enable 
the TLS connection using a self signed certificate. 
   The client initiate the connection using an internal domain to the DB and 
verifying the self-signed CA certificate of this TLS connection.
   Suggest to add the support of this common practice in the Helm Chart by 
   1. adding the configuration of the DB SSL connection with the CA certificate 
Configuration. It would be great if it can refer to a Kubernetes Secret
   2. Add hostAliases in the helm chart 
(https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/) so 
that the pod can go to the DB using an internal FQDN. The internal FQDN is also 
used in the TLS certificate, so we need to use it to connect to DB so that the 
server can use the correct server certificate
   
   ### Use case
   
   _No response_
   
   ### Related issues
   
   _No response_
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: 
[email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to