UNCLASSIFIED - NO CUI

Skip to content

Istiod package is not passed jwksResolverExtraRootCA

Bug

Description

It looks like the bigbang chart doesn't pass along the .sso.certificateAuthority to the new istiod which prevents authservice working with a Keycloak that has self-signed certs or non-publically trusted certs.

We can work around by passing the values to the upstream chart, but would be more convenient if the new istiod integration with BB also support the global sso CA cert when configured.

For context, we pass the cert here as part of the values for the istio chart.

Ideally we do the same for istiod as well.

BigBang Version

2.52