feat(server): separate HTTPS from mTLS authentication (#1351)

Make --tls-client-ca optional and make client certificates always
optional when a CA is configured. This decouples HTTPS encryption
from mTLS authentication, allowing mTLS and OIDC bearer tokens to
coexist as parallel authentication mechanisms.

When --tls-client-ca is provided, client certificates are validated
against the CA when presented but never required. Clients may connect
with or without a certificate — authentication is handled at the
application layer (e.g. OIDC).

Two TLS modes are now supported:
- HTTPS with optional mTLS (--tls-client-ca provided)
- HTTPS-only (--tls-client-ca omitted)

The --disable-gateway-auth flag is preserved for backward
compatibility but is now a no-op. The allow_unauthenticated field
has been removed from TlsConfig. The Helm chart conditionally
includes the client-ca volume and env var based on whether
clientCaSecretName is configured.
This commit is contained in:
Seth Jennings
2026-05-15 09:43:30 -07:00
committed by GitHub
parent 9f8edb5a45
commit c94cddbfb8
21 changed files with 423 additions and 240 deletions
+3
View File
@@ -86,6 +86,9 @@ pub fn generate_pki(extra_sans: &[String]) -> Result<PkiBundle> {
client_params
.distinguished_name
.push(DnType::CommonName, "openshell-client");
client_params
.distinguished_name
.push(DnType::OrganizationalUnitName, "openshell-user");
let client_cert = client_params
.signed_by(&client_key, &ca_cert, &ca_key)