-
Notifications
You must be signed in to change notification settings - Fork 1.8k
fix: add Google CA to certificate store in fluent-bit Windows image #11070
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
WalkthroughThe Windows Dockerfile now installs the Google Root CA certificate in both builder and runtime stages via PowerShell, enabling communication with Google Cloud services. Minor formatting adjustments were applied to multi-line shell commands without behavioral changes. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
Pre-merge checks and finishing touches❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✨ Finishing touches🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: CodeRabbit UI Review profile: CHILL Plan: Pro 📒 Files selected for processing (1)
🔇 Additional comments (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think we should be fetching random certificates from internet. Why is this not bundled in the default windows cert store?
Windows only ships the Microsoft CA into the base image that is used by fluent-bit to create the Windows Container image.
This means, that all requests to Google signed SSL endpoints - fail.
This PR, adds the Google CA.
Summary by CodeRabbit