Skip to content

Conversation

@sorenmat
Copy link

@sorenmat sorenmat commented Dec 14, 2023

K8SPSMDB-1062 Powered by Pull Request Badge

CHANGE DESCRIPTION

Problem:
When running in Istio (perhaps other serice meshes) we need to set the appProtocol to mongo.
This is needed since mongo is a server first protocol, which breaks the mTLS protocol

Cause:

A mongo cluster is not able to form.

Solution:

Just adding mongo as an appProtocol see: https://kubernetes.io/docs/concepts/services-networking/service/#application-protocol

CHECKLIST

Jira

  • Is the Jira ticket created and referenced properly?
  • Does the Jira ticket have the proper statuses for documentation (Needs Doc) and QA (Needs QA)?
  • Does the Jira ticket link to the proper milestone (Fix Version field)?

Tests

  • Is an E2E test/test case added for the new feature/change?
  • Are unit tests added where appropriate?
  • Are OpenShift compare files changed for E2E tests (compare/*-oc.yml)?

Config/Logging/Testability

  • Are all needed new/changed options added to default YAML files?
  • Are the manifests (crd/bundle) regenerated if needed?
  • Did we add proper logging messages for operator actions?
  • Did we ensure compatibility with the previous version or cluster upgrade process?
  • Does the change support oldest and newest supported MongoDB version?
  • Does the change support oldest and newest supported Kubernetes version?

@CLAassistant
Copy link

CLAassistant commented Dec 14, 2023

CLA assistant check
All committers have signed the CLA.

@egegunes egegunes self-assigned this Dec 14, 2023
@hors hors added the community label Dec 14, 2023
@egegunes egegunes added this to the v1.16.0 milestone Jan 12, 2024
Copy link
Collaborator

@hors hors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sorenmat please check and fix tests

@pull-request-size pull-request-size bot added size/S 10-29 lines and removed size/XS 0-9 lines labels Jan 16, 2024
@egegunes
Copy link
Contributor

egegunes commented Feb 2, 2024

@sorenmat ping

@sorenmat
Copy link
Author

sorenmat commented Feb 2, 2024

I'm on it... 👍🏼 sorry for the delay

@sorenmat sorenmat force-pushed the appProtocol branch 2 times, most recently from 3491eb0 to df4b668 Compare February 5, 2024 13:02
@pull-request-size pull-request-size bot added size/M 30-99 lines and removed size/S 10-29 lines labels Feb 5, 2024
@egegunes
Copy link
Contributor

egegunes commented Feb 9, 2024

@sorenmat please ensure that you add this new field to every service controlled by the operator

@sorenmat sorenmat force-pushed the appProtocol branch 2 times, most recently from c9c7eb9 to 61dc1f1 Compare February 22, 2024 07:53
@pull-request-size pull-request-size bot added size/S 10-29 lines and removed size/M 30-99 lines labels Feb 22, 2024
@egegunes
Copy link
Contributor

egegunes commented Mar 1, 2024

Hi @sorenmat! We're working on next PSMDB operator release and if you finish this PR in next 2 weeks we can include this.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds support for setting appProtocol: mongo on Kubernetes service objects to enable proper operation within service meshes like Istio. Since MongoDB uses a server-first protocol that can break mTLS negotiation, explicitly declaring the protocol allows service meshes to handle the traffic correctly.

Key Changes:

  • Added appProtocol: mongo to service ports for operator version 1.22.0 and above
  • Updated test comparison files to reflect the new service configuration

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
pkg/psmdb/service.go Added version-gated logic to set appProtocol: mongo on service ports in both Service() and ExternalService() functions
e2e-tests/upgrade-consistency/compare/service_some-name-rs0-1201.yml Updated expected service configuration to include appProtocol: mongo
e2e-tests/upgrade-consistency-sharded-tls/compare/service_some-name-cfg-1220.yml Updated expected service configuration to include appProtocol: mongo
e2e-tests/monitoring-pmm3/compare/service_monitoring-pmm3-rs0.yml Updated expected service configuration to include appProtocol: mongo

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@pull-request-size pull-request-size bot added size/M 30-99 lines and removed size/S 10-29 lines labels Dec 16, 2025
Copilot AI review requested due to automatic review settings December 16, 2025 10:02
@pull-request-size pull-request-size bot added size/L 100-499 lines and removed size/M 30-99 lines labels Dec 16, 2025
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 32 out of 32 changed files in this pull request and generated 4 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copilot AI review requested due to automatic review settings December 16, 2025 10:51
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 37 out of 37 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Contributor

@egegunes egegunes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

there's a diff in init-deploy

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 39 out of 39 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@hors hors requested a review from mayankshah1607 December 18, 2025 20:58
@JNKPercona
Copy link
Collaborator

Test Name Result Time
arbiter passed 00:00:00
balancer passed 00:00:00
cross-site-sharded passed 00:00:00
custom-replset-name passed 00:00:00
custom-tls passed 00:00:00
custom-users-roles passed 00:00:00
custom-users-roles-sharded passed 00:00:00
data-at-rest-encryption passed 00:00:00
data-sharded passed 00:00:00
demand-backup passed 00:00:00
demand-backup-eks-credentials-irsa passed 00:00:00
demand-backup-fs passed 00:00:00
demand-backup-if-unhealthy passed 00:00:00
demand-backup-incremental passed 00:00:00
demand-backup-incremental-sharded passed 00:59:46
demand-backup-physical-parallel passed 00:00:00
demand-backup-physical-aws passed 00:00:00
demand-backup-physical-azure passed 00:00:00
demand-backup-physical-gcp-s3 passed 00:00:00
demand-backup-physical-gcp-native passed 00:00:00
demand-backup-physical-minio passed 00:00:00
demand-backup-physical-minio-native passed 00:00:00
demand-backup-physical-sharded-parallel passed 00:00:00
demand-backup-physical-sharded-aws passed 00:00:00
demand-backup-physical-sharded-azure passed 00:00:00
demand-backup-physical-sharded-gcp-native passed 00:00:00
demand-backup-physical-sharded-minio passed 00:00:00
demand-backup-physical-sharded-minio-native passed 00:00:00
demand-backup-sharded passed 00:00:00
expose-sharded passed 00:00:00
finalizer passed 00:00:00
ignore-labels-annotations passed 00:00:00
init-deploy passed 00:00:00
ldap passed 00:00:00
ldap-tls passed 00:00:00
limits passed 00:00:00
liveness passed 00:00:00
mongod-major-upgrade passed 00:00:00
mongod-major-upgrade-sharded passed 00:00:00
monitoring-2-0 passed 00:00:00
monitoring-pmm3 passed 00:00:00
multi-cluster-service passed 00:00:00
multi-storage passed 00:00:00
non-voting-and-hidden passed 00:00:00
one-pod passed 00:00:00
operator-self-healing-chaos passed 00:00:00
pitr passed 00:00:00
pitr-physical passed 00:00:00
pitr-sharded passed 00:00:00
pitr-to-new-cluster passed 00:00:00
pitr-physical-backup-source passed 00:00:00
preinit-updates passed 00:00:00
pvc-resize passed 00:00:00
recover-no-primary passed 00:00:00
replset-overrides passed 00:00:00
rs-shard-migration passed 00:00:00
scaling passed 00:00:00
scheduled-backup passed 00:00:00
security-context passed 00:00:00
self-healing-chaos passed 00:00:00
service-per-pod passed 00:00:00
serviceless-external-nodes passed 00:00:00
smart-update passed 00:00:00
split-horizon passed 00:00:00
stable-resource-version passed 00:00:00
storage passed 00:00:00
tls-issue-cert-manager passed 00:00:00
upgrade passed 00:00:00
upgrade-consistency passed 00:00:00
upgrade-consistency-sharded-tls passed 00:00:00
upgrade-sharded passed 00:00:00
upgrade-partial-backup passed 00:00:00
users passed 00:00:00
version-service passed 00:00:00
Summary Value
Tests Run 74/74
Job Duration 01:29:57
Total Test Time 00:59:46

commit: 371bdb6
image: perconalab/percona-server-mongodb-operator:PR-1393-371bdb64

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community size/L 100-499 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants