Hi Hasitha, We really appreciate your interest in Custos project. Please find the inline comments.
On Tue, May 11, 2021 at 9:33 AM Hasitha Jayasundara < [email protected]> wrote: > Hi all, > > I'm Hasitha and I'm currently working as a Full Stack Engineer for a UK > based tech company. I graduated from University Of Moratuwa Department of > Electronic and Telecommunication Engineering Sri Lanka and completed a > software engineering internship at a company called WSO2 which is an open > source technology provider based in Sri Lanka. I also participated in > Google Summer of Code 2017 and successfully completed a project for > implementing an inbound endpoint and a connector for IBM-MQ. > > I'm enthusiastic about the airavata-custos project and would be extremely > interested in contributing to the project. I've already followed the wiki > page[1] and the tutorial presented at the Gateways 2020 Conference [2] and > I think I have a clear understanding about how custos operates in the real > world. > > As a starting point I selected the issue #152 [3] which is to implement a > cert manager task using Custos. The idea is to automate the cert renewal > process so that the client's won't need to manually do it by going through > Let's Encrypt cert renewal process. The task (cron job) will be responsible > for, > > - Connecting to Let’s Encrypt APIs and create certificates, update > certificates > - Saving updated certificates into a given location and where the server > application can use it > > The overall process can be illustrated as follows. > > > > - Custos Cert Renewer task (Cron Job) will be executed on periodic > configurable time period > - Task will communicate with Let's Encrypt using ACME(Automated > Certificate Management Environments) protocol. (I've already tested this > with acme4j [4] which is a java client for ACME protocol and it's > working > fine without any issues) > - Task will then obtain the updated certificate and store it in a given > path in Custos (probably in a persistent volume) > - Client applications can query certificates from Custos and add them to > client trustore on demand to call a server application > > Following I listed out some of the concerns I'm having at the moment. > > - In order to obtain an updated certificates, > > > 1. we need to have an account in CA with a public and a private key > pair. Do we already have an account in Let's Encrypt for this type of > work > or Is it possible to create a dedicated account for the cert renewer > task? > yes, we can create a test account in Let's Encrypt. 2. we need to provide CNs (domain names) for Let's Encrypt. Where do we > store the domain names of the clients? > I guess you are referring to the server application domains. those should be configurable and can be stored in a configuration file. > - After obtaining the certificate, it's required to save it in Custos in > a given path. Do we already have an endpoint to achieve this? > Yes, Custos has a secret management service to save certificates. > - Client applications can query the certificates in Custos. How can we > provide the clients the information about the path to query? > Client applications can use Custos service accounts to access Custos APIs, > > Please have a look at the above and let me know your opinion. > > Regards > > [1]. > > https://cwiki.apache.org/confluence/display/CUSTOS/Custos+Architecture+and+Internals > [2]. https://youtu.be/CuBvFj194Kg > [3]. https://github.com/apache/airavata-custos/issues/152 > [4]. https://github.com/shred/acme4j > -- Research Software Engineer Indiana University, IN
