Context
Node-to-node Raft traffic is currently plaintext HTTP. It should instead run over mTLS, authenticated against a per-participant CA. Each participant operates a private CA and issues one certificate per node. Every node holds the list of CAs its participants trusts. A Raft listener accepts a connection only from a certificate signed by a trusted CA.
Scope
- Trusted-CA list + per-node certificate
- mTLS on Raft connections
Expected result
- An unauthenticated or untrusted-CA connection is rejected on all three Raft listeners
- A CA installed on some nodes and not others does not break silently
This issue will be refined with the design details.
Context
Node-to-node Raft traffic is currently plaintext HTTP. It should instead run over mTLS, authenticated against a per-participant CA. Each participant operates a private CA and issues one certificate per node. Every node holds the list of CAs its participants trusts. A Raft listener accepts a connection only from a certificate signed by a trusted CA.
Scope
Expected result
This issue will be refined with the design details.