Hi, The changes in the PR should be already in Tentacle so the fix will come with the release. In addition I'd recommend in general puting any service related config in the service-spec. Setting the key-store by hand directly is not a good idea as cephadm will not be aware of those changes and can potentially override them. We are working in a more user-friendly support to manage certificates in cephadm: https://github.com/ceph/ceph/pull/62106 But that would take some time to land into an official release. Best, Redo. On Tue, Jul 8, 2025 at 3:13 PM Daniel Parkes <dparkes@redhat.com> wrote:
Hi,
I would expect it to be backported into Tentacle. Maybe Adam or Redo can confirm?
Thanks,
Regards.
On Mon, Jul 7, 2025 at 2:10 PM Boris <bb@kervyn.de> wrote:
Hi Daniel,
do you know when this will be released?
I can not find the change in the changelogs for reef or squid, and I updated the certificate/key with ceph config-key set rgw/cert/rgw.s3-poc-boris -i /etc/letsencrypt/data/s3-poc-boris_ecc/s3-poc-boris.pem (the pem contains cert and key combined)
I did not provide and keys in the ceph orch yaml, but put the certificate at the location which seems to be deterministic to the service name.
Am Sa., 5. Juli 2025 um 16:11 Uhr schrieb Daniel Parkes < dparkes@redhat.com>:
Hi Boris,
When using cephadm as the orchestrator, this request has been addressed in the following PR: https://github.com/ceph/ceph/pull/61694
https://tracker.ceph.com/issues/69863
Regards.
On Fri, Jul 4, 2025 at 1:32 PM Boris <bb@kervyn.de> wrote:
Hi, is there a way to reload the ceritificate in rgw without downtime? Or if I have multiple rgw daemons to do it one by one and wait for the last one to be active again?
-- Die Selbsthilfegruppe "UTF-8-Probleme" trifft sich diesmal abweichend im groüen Saal. _______________________________________________ ceph-users mailing list -- ceph-users@ceph.io To unsubscribe send an email to ceph-users-leave@ceph.io
-- Die Selbsthilfegruppe "UTF-8-Probleme" trifft sich diesmal abweichend im groüen Saal.