Does Kubeflow automatically trust the cluster's CA bundle for external HTTPS calls from pipeline components?
27.5K reputation · 12 Jul 2020, 12:52 UTC
The goal is to determine whether a Kubeflow pipeline pod can validate TLS certificates of external HTTPS endpoints without manually adding the cluster’s root CA bundle to the container image.
Current behavior varies with the pod’s base OS, the presence of the SSL_CERT_FILE environment variable, and whether the kube-root-ca.crt volume mount is automatically applied, which differs between Kubeflow versions and ingress controllers such as Istio or NGINX.
Uncertainty remains about the default trust configuration and how DNS resolution interacts with certificate validation when external services are accessed.
Is the kube-root-ca.crt mount automatically added to all pipeline pods? Does the default SSL_CERT_FILE point to that mount when present? How does the trust behavior differ between Kubeflow v1.4 and v1.6?