Hi Hasitha, Great progress. You can start Custos integration using custos-java-sdk[1]. There could be some unimplemented methods and it would be great if you can implement and submit PRs.
thanks Isuru [1] https://github.com/apache/airavata-custos/tree/develop/custos-client-sdks/custos-java-sdk On Mon, May 17, 2021 at 11:59 PM Hasitha Jayasundara < [email protected]> wrote: > Hi Isuru, > > I completed the cert renewal part of the feature and the implementation can > be found at [1]. > > At the moment I'm doing some refactoring according to acme protocol best > practices. After that I'm hoping to start working on custos integration > part of the feature using Java SDK. Basically the idea is to store the > updated certificates in Custos. > > I am using pebble [2] (a lightweight version of letsencrypt boulder CA > server) as the CA server for testing purposes. The main reason for using > Pebble is that the Lets Encrypt CA server endpoint (staging) is not > working as expected in the dev environment for a fake domain. > > As for the current implementation I'm using a nginx server with Lua module > as acme challenge server to store files required for completing the > challenge. Lua module is used to embed Lua programming language into nginx > server and create files required for acme challenge. (CGI with Nginx and > SpringBoot are two other options for this and I'm thinking of do a proper > poc/rfc after initial feature implementation is completed) > > Regards > > [1]. https://github.com/hasithajayasundara/cert-updater > [2]. https://github.com/letsencrypt/pebble > > On Fri, May 14, 2021 at 2:41 PM Hasitha Jayasundara < > [email protected]> wrote: > > > Hi Isuru, > > > > Thanks for the explanation. I think I have a clear idea on how to proceed > > with the Let's Encrypt part of the implementation now. > > > > I already started the implementation and am currently designing a > solution > > for handling the Let's Encrypt challenge. Once that is done I am thinking > > of starting the certificates store process in Custos. I think I'll > probably > > need some setup completed first for making authenticated requests to > Custos. > > > > Found an issue with the certificate store path in the current > > implementation and I've sent a fix for that. [1] > > > > Regards > > > > [1]. https://github.com/apache/airavata-custos/pull/160 > > > > On Thu, May 13, 2021 at 9:31 AM Isuru Ranawaka <[email protected]> > wrote: > > > >> Hi Hasitha, > >> > >> Glad to hear that you have gone through the code. Please feel free to > >> submit bug fixes as you see. > >> > >> We use HarshiCorp vault to store secrets. The paths you mentioned are > >> actually created in the vault. Precisely, owner_id is the id of the user > >> or > >> the service account that owns the certificate. Token is an identifier > that > >> can be used to retrieve the certificate later. > >> > >> thanks > >> Isuru > >> > >> On Wed, May 12, 2021 at 11:08 PM Hasitha Jayasundara < > >> [email protected]> wrote: > >> > >> > Hi Isuru, > >> > > >> > Thanks for the reply. Based on your comment that custos already has an > >> > endpoint to store certificates I took some time to go through the > Secret > >> > Management Service and the proto for Resource Secret Service. > >> > > >> > According to my observation, I think I can use *POST - > >> > /resource-secret-management/v1.0.0/secret/certificate* endpoint to do > >> > certificate uploading. (Correct me if I'm wrong) > >> > > >> > Going through the code I found that certificate is stored in > >> > */resourcesecret/<tenant_id>/<owner_id>/ssh/<token>*. The <tenant_id>, > >> > <owner_id> and <token> are received through the request body. I am not > >> 100% > >> > clear about <owner_id> and <token> fields in the context of custos > >> secret > >> > manager service. Could you please explain a bit about <owner_id> and > the > >> > <token>? > >> > > >> > Regards > >> > > >> > On Wed, May 12, 2021 at 7:30 AM Isuru Ranawaka <[email protected]> > >> wrote: > >> > > >> > > Hi Hasitha, > >> > > > >> > > We really appreciate your interest in Custos project. Please find > the > >> > > inline comments. > >> > > > >> > > On Tue, May 11, 2021 at 9:33 AM Hasitha Jayasundara < > >> > > [email protected]> wrote: > >> > > > >> > > > Hi all, > >> > > > > >> > > > I'm Hasitha and I'm currently working as a Full Stack Engineer for > >> a UK > >> > > > based tech company. I graduated from University Of Moratuwa > >> Department > >> > of > >> > > > Electronic and Telecommunication Engineering Sri Lanka and > >> completed a > >> > > > software engineering internship at a company called WSO2 which is > an > >> > open > >> > > > source technology provider based in Sri Lanka. I also participated > >> in > >> > > > Google Summer of Code 2017 and successfully completed a project > for > >> > > > implementing an inbound endpoint and a connector for IBM-MQ. > >> > > > > >> > > > I'm enthusiastic about the airavata-custos project and would be > >> > extremely > >> > > > interested in contributing to the project. I've already followed > the > >> > wiki > >> > > > page[1] and the tutorial presented at the Gateways 2020 Conference > >> [2] > >> > > and > >> > > > I think I have a clear understanding about how custos operates in > >> the > >> > > real > >> > > > world. > >> > > > > >> > > > As a starting point I selected the issue #152 [3] which is to > >> > implement a > >> > > > cert manager task using Custos. The idea is to automate the cert > >> > renewal > >> > > > process so that the client's won't need to manually do it by going > >> > > through > >> > > > Let's Encrypt cert renewal process. The task (cron job) will be > >> > > responsible > >> > > > for, > >> > > > > >> > > > - Connecting to Let’s Encrypt APIs and create certificates, > >> update > >> > > > certificates > >> > > > - Saving updated certificates into a given location and where > the > >> > > server > >> > > > application can use it > >> > > > > >> > > > The overall process can be illustrated as follows. > >> > > > > >> > > > > >> > > > > >> > > > - Custos Cert Renewer task (Cron Job) will be executed on > >> periodic > >> > > > configurable time period > >> > > > - Task will communicate with Let's Encrypt using ACME(Automated > >> > > > Certificate Management Environments) protocol. (I've already > >> tested > >> > > this > >> > > > with acme4j [4] which is a java client for ACME protocol and > it's > >> > > > working > >> > > > fine without any issues) > >> > > > - Task will then obtain the updated certificate and store it > in a > >> > > given > >> > > > path in Custos (probably in a persistent volume) > >> > > > - Client applications can query certificates from Custos and > add > >> > them > >> > > to > >> > > > client trustore on demand to call a server application > >> > > > > >> > > > Following I listed out some of the concerns I'm having at the > >> moment. > >> > > > > >> > > > - In order to obtain an updated certificates, > >> > > > > >> > > > > >> > > > 1. we need to have an account in CA with a public and a private > >> key > >> > > > pair. Do we already have an account in Let's Encrypt for this > >> type > >> > of > >> > > > work > >> > > > or Is it possible to create a dedicated account for the cert > >> renewer > >> > > > task? > >> > > > > >> > > > >> > > yes, we can create a test account in Let's Encrypt. > >> > > > >> > > 2. we need to provide CNs (domain names) for Let's Encrypt. Where > >> do > >> > we > >> > > > store the domain names of the clients? > >> > > > > >> > > > >> > > I guess you are referring to the server application domains. those > >> should > >> > > be configurable and can be stored in a configuration file. > >> > > > >> > > > >> > > > - After obtaining the certificate, it's required to save it in > >> > Custos > >> > > in > >> > > > a given path. Do we already have an endpoint to achieve this? > >> > > > > >> > > > >> > > Yes, Custos has a secret management service to save certificates. > >> > > > >> > > > >> > > > - Client applications can query the certificates in Custos. How > >> can > >> > we > >> > > > provide the clients the information about the path to query? > >> > > > > >> > > > >> > > > >> > > Client applications can use Custos service accounts to access Custos > >> > APIs, > >> > > > >> > > > >> > > > > >> > > > Please have a look at the above and let me know your opinion. > >> > > > > >> > > > Regards > >> > > > > >> > > > [1]. > >> > > > > >> > > > > >> > > > >> > > >> > https://cwiki.apache.org/confluence/display/CUSTOS/Custos+Architecture+and+Internals > >> > > > [2]. https://youtu.be/CuBvFj194Kg > >> > > > [3]. https://github.com/apache/airavata-custos/issues/152 > >> > > > [4]. https://github.com/shred/acme4j > >> > > > > >> > > > >> > > > >> > > -- > >> > > Research Software Engineer > >> > > Indiana University, IN > >> > > > >> > > >> > >> > >> -- > >> Research Software Engineer > >> Indiana University, IN > >> > > > -- Research Software Engineer Indiana University, IN
