OVDC: TLS Configuration#
This guide covers enabling TLS encryption for inter-cluster cache communication.
Note
In-cluster transport is plaintext by default
(settings.grpcTls.enabled: false). This is a deliberate default—a
workload Helm chart cannot mint certificates for itself at install time,
so in-cluster service-to-service encryption is typically provided by a
service mesh or operator-issued certificates. TLS support exists and can
be switched on with an operator-supplied Secret, as covered below.
1. Create the TLS Secret#
Create a Kubernetes TLS secret with your certificate and key:
kubectl create secret tls ovdc-tls \
--cert=tls.crt \
--key=tls.key \
--namespace ovdc
Important
The internal service URL MUST be included as a common name on the
certificate. For example, if your release name is ovdc, the
certificate should include
ovdc-ovderivedcache-N.<service>.svc.cluster.local as a common name,
matching each pod’s headless Service DNS entry.
Self-Signed Certificate (Reference Only)#
For testing purposes only, you can create a self-signed certificate using OpenSSL:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
-keyout tls.key -out tls.crt \
-subj "/CN=*.ovdc.svc.cluster.local"
Warning
Self-signed certificates should NOT be used in production environments. Use certificates from a trusted Certificate Authority (CA) for production deployments.
2. Enable TLS in values.yaml#
After creating the TLS secret, enable TLS in your values.yaml file
under settings.grpcTls. Unlike other gRPC settings, the certificate
and key paths are fixed by the chart at /etc/ovdc/tls and are
not configurable—only the Secret name is.
settings:
grpcTls:
# Require TLS on the gRPC listener.
enabled: true
# Name of the Kubernetes TLS secret created in step 1.
secretName: ovdc-tls
The chart mounts the named Secret read-only at /etc/ovdc/tls and
points the application at /etc/ovdc/tls/tls.crt and
/etc/ovdc/tls/tls.key. secretName is required when enabled
is true; the render fails otherwise. This section of settings is
read once at startup, so changing it requires a pod restart.
settings.grpcTls Field Reference#
Field |
Type |
Required |
Default |
Description |
|---|---|---|---|---|
|
boolean |
No |
|
Requires
TLS on the
gRPC
listener
when
|
|
string |
Yes, when
|
|
Name of the
Kubernetes
TLS Secret
to mount.
The render
fails if
|
|
boolean |
No |
|
When
|
3. Optional: Configure CA Root Certificate#
If your deployment requires a custom CA root certificate for validation,
enable includeCaRoot. The Secret must then also carry a ca.crt
key, which kubectl create secret tls does not add on its own:
kubectl create secret generic ovdc-tls -n ovdc \
--from-file=tls.crt=cert.pem \
--from-file=tls.key=key.pem \
--from-file=ca.crt=ca.pem
settings:
grpcTls:
enabled: true
secretName: ovdc-tls
includeCaRoot: true
When includeCaRoot is true, the application reads
/etc/ovdc/tls/ca.crt as the CA root.
4. Complete Example Configuration#
Here is a complete example showing TLS configuration within a typical
OVDC values.yaml:
image:
pullSecrets:
- name: regcred
replicas: 1
resources:
requests:
memory: 56G
storage:
volume:
size: 330Gi
storageClassName: "gp3"
settings:
store:
maxSize: AUTO
engine:
cacheSize: "32G"
blockCacheSize: "8G"
grpcTls:
enabled: true
secretName: ovdc-tls
5. Apply Configuration Changes#
After updating your values.yaml file with TLS configuration, apply
the changes using Helm:
helm upgrade ovdc omniverse/ovderivedcache \
--version 6.0.0 \
--namespace ovdc \
-f values.yaml
If you are installing OVDC for the first time with TLS enabled:
helm install ovdc omniverse/ovderivedcache \
--version 6.0.0 \
--namespace ovdc \
-f values.yaml
6. Verify TLS Configuration#
After applying the configuration, verify that TLS is enabled:
# Check that the TLS secret is mounted in the pod
kubectl describe pod -n ovdc -l app.kubernetes.io/instance=ovdc | grep -A 5 "Mounts:"
# Verify the pod is running successfully
kubectl get pods -n ovdc -l app.kubernetes.io/instance=ovdc
The TLS secret will be mounted at /etc/ovdc/tls within the pod, and
the pod should be running without errors.
Summary#
For deployment instructions, refer to the deployment guide. For general configuration options, refer to the configuration guide.