-
Notifications
You must be signed in to change notification settings - Fork 21
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade RDS certificate on Production #3309
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
github-actions
bot
added
enhancement
New feature or request
Infra
Issues related to the infrastructure underlying all the tools.
terraform
Pull requests that update Terraform code
labels
Jul 29, 2024
QA Summary
Test CoverageCoverage report for `packages/client`
Coverage report for `packages/server`
|
Terraform Summary
Hint: If "Terraform Format & Style" failed, run OutputValidation Output
Plan Summary
Pusher: @TylerHendrickson, Action: |
as1729
approved these changes
Jul 30, 2024
TylerHendrickson
added
the
database-changes
Includes schema migrations or other critical changes
label
Aug 8, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
database-changes
Includes schema migrations or other critical changes
enhancement
New feature or request
Infra
Issues related to the infrastructure underlying all the tools.
terraform
Pull requests that update Terraform code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR adjusts the configuration for the RDS Aurora SSL/TLS certificate in the Production environment. It also configures the
postgres_ca_cert_identifier
Terraform input variable with a default value ofrds-ca-rsa-2048-g1
, since that value is now shared by all targeted environments.Note that #3273 updated the CA bundle file used to verify SSL/TLS connections, and #3286 applied the same configuration change in Staging. Now that we have successfully rotated the Staging environment certificate from
rds-ca-2019
tords-ca-rsa-2048-g1
without any problems or downtime, we should be able to safely apply the same upgrade operation while targeting Production.As with #3286, changes from this pull request will not take effect immediately. Rather, the upgrade will be a pending action for the next RDS maintenance window, which is currently scheduled to run on Sunday, August 04, 2024 at 1am Eastern.
This PR is expected to conclude changes related to the planned August 22, 2024 expiration of the
rds-ca-2019
certificate authority.