DNS Strategy: TLS Certificate Validation Limits in Moleculer
0 reputation · 05 Jul 2021, 23:18 UTC
Goal
Determine how Moleculer’s DNS service discovery strategy handles TLS certificate validation when connecting to discovered services, and whether a unified policy can be enforced.
Constraints
The framework’s DNS strategy resolves SRV records but delegates connection security to individual transporters (e.g., NATS, MQTT, Redis). Transporter implementations expose TLS options such as rejectUnauthorized, yet the behavior and default settings differ across versions. Moleculer‑web supports HTTPS for the gateway, but it does not provide a direct API to enforce client certificate validation for incoming requests. Consequently, there is no out‑of‑the‑box mechanism to guarantee mutual TLS (mTLS) for services discovered via DNS.
Unresolved Decision
Should the DNS strategy enforce mTLS for all discovered services, or should each transporter remain responsible for its own certificate validation?
Questions
- What is the current default behavior of the DNS strategy regarding TLS certificate validation across different transporter modules?
- Can a global configuration be added to Moleculer that forces mTLS for all services resolved through DNS, regardless of the underlying transporter?
- What are the security implications of leaving certificate validation to individual transporters in a production deployment?