Skip to content

Feat/devlake mysql ssl - #108

Open
kpiwko wants to merge 2 commits into
konflux-ci:mainfrom
kpiwko:feat/devlake-mysql-ssl
Open

kpiwko wants to merge 2 commits into
konflux-ci:mainfrom
kpiwko:feat/devlake-mysql-ssl

Conversation

@kpiwko

@kpiwko kpiwko commented Jun 18, 2026

Copy link
Copy Markdown

⚠️ Pre Checklist

Please complete ALL items in this checklist, and remove before submitting

  • I have read through the Contributing Documentation.
  • I have added relevant tests.
  • I have added relevant documentation.
  • I will add labels to the PR, such as pr-type/bug-fix, pr-type/feature-development, etc.

Summary

What does this PR do?

Does this close any open issues?

Closes xx

Screenshots

Include any relevant screenshots here.

Other Information

Any other information that is important to this PR.

kpiwko and others added 2 commits June 18, 2026 15:49
The SSL code path in MakeDbConnection was using an empty gorm.Config{}
instead of the conf parameter, silently dropping logging and session
settings when TLS was enabled.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…h TLS

Mounts the RDS CA bundle at the OpenShift CA path and sets SSL_CERT_FILE
so Go's SystemCertPool() finds it. Uses tls=true, mirroring staging.
@qodo-app-for-konflux-ci

Copy link
Copy Markdown

Code Review by Qodo

Grey Divider

Sorry, something went wrong

We weren't able to complete the code review on our side. Please try again

Grey Divider

Qodo Logo

@qodo-app-for-konflux-ci

Copy link
Copy Markdown

PR Summary by Qodo

MySQL TLS: preserve GORM config and add external DB compose overlay
🐞 Bug fix ✨ Enhancement ⚙️ Configuration changes 📝 Documentation 🧪 Tests 🕐 20-40 Minutes

Grey Divider

Description

• Preserve caller-provided GORM config when connecting to MySQL via custom TLS.
• Add docker-compose overlay to run DevLake against remote MySQL/RDS with tls=true.
• Document SSL DB env vars and add unit coverage for DSN query sanitization.
Diagram

graph TD
  A["docker-compose-external-db.yml"] --> B["DevLake container"] --> C["DB_URL (tls=true)"] --> D["MakeDbConnection()"] --> E["go-sql-driver/mysql"] --> F[("Remote MySQL/RDS")]
  A --> G["CA bundle + SSL_CERT_FILE"] --> E
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Use `tls=custom&ca-cert=/path/to/ca.pem` everywhere
  • ➕ Avoids relying on Go's SystemCertPool/SSL_CERT_FILE behavior differences across distros
  • ➕ Explicitly ties the DB URL to a specific CA file, reducing implicit platform coupling
  • ➖ Requires mounting a CA file path and keeping it consistent across environments
  • ➖ Adds custom TLS config registration complexity and DSN parameters (must keep ca-cert stripping correct)
2. Bake the RDS CA bundle into the image trust store
  • ➕ Eliminates runtime mounts/env wiring for SSL_CERT_FILE in most deployments
  • ➕ Keeps tls=true semantics without extra compose/helm overlays
  • ➖ Harder to rotate CA bundles without rebuilding/redeploying images
  • ➖ May be undesirable if different clusters/databases require different trust roots

Recommendation: The PR’s approach is sound for local development because it mirrors the deployed pattern (tls=true + CA injection) while fixing a real correctness issue (dropping the caller’s gorm.Config on the TLS path). Consider the tls=custom&amp;ca-cert=... approach only if environment-to-environment CA discovery (SystemCertPool/SSL_CERT_FILE) continues to be a recurring source of outages.

Files changed (5) +397 / -41

Bug fix (1) +1 / -1
db.goUse provided *gorm.Config on MySQL custom-TLS connection path +1/-1

Use provided *gorm.Config on MySQL custom-TLS connection path

• Fixes MakeDbConnection’s MySQL TLS branch to pass through the caller-provided gorm.Config instead of an empty config. This prevents losing GORM logger/session settings when 'tls' and 'ca-cert' are used together.

backend/core/runner/db.go

Tests (1) +26 / -40
db_test.goAdd unit tests for MySQL DSN query sanitization +26/-40

Add unit tests for MySQL DSN query sanitization

• Replaces the previous local/loc-related test coverage with focused tests for sanitizeQuery. Verifies 'ca-cert' is removed from the encoded query and that 'loc' is preserved or defaulted to Local.

backend/core/runner/db_test.go

Documentation (1) +328 / -0
2026-06-18-devlake-mysql-ssl.mdAdd implementation plan for enforcing MySQL SSL across environments +328/-0

Add implementation plan for enforcing MySQL SSL across environments

• Documents the rationale, constraints, and step-by-step plan for enabling MySQL/RDS TLS in local compose and Helm-based deployments. Captures the Debian vs OpenShift CA path mismatch and recommended mitigations.

docs/superpowers/plans/2026-06-18-devlake-mysql-ssl.md

Other (2) +42 / -0
docker-compose-external-db.ymlAdd compose overlay for remote MySQL/RDS with TLS verification +32/-0

Add compose overlay for remote MySQL/RDS with TLS verification

• Introduces a docker-compose overlay that mounts an RDS CA bundle to the OpenShift CA path and sets SSL_CERT_FILE so Go can find it. Overrides DB_URL to use 'tls=true' for remote DB connections.

docker-compose-external-db.yml

env.exampleDocument DB_SSL_* variables for the external DB TLS overlay +10/-0

Document DB_SSL_* variables for the external DB TLS overlay

• Adds commented environment variable templates for configuring remote MySQL/RDS connectivity when using docker-compose-external-db.yml. Keeps existing defaults unchanged while making the SSL overlay discoverable.

env.example

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant