Skip to content

[patch] Update CLI issuerKind derivation for MAS 9.3+ - #2607

Merged
praiyani6789 merged 7 commits into
masterfrom
pr.kind-temp
Oct 7, 2026
Merged

praiyani6789 merged 7 commits into
masterfrom
pr.kind-temp

Conversation

@praiyani6789

@praiyani6789 praiyani6789 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Description

In MAS 9.2, issuerKind controlled both internal and external certificate issuance, so the CLI had to prompt users for it and enforce that ClusterIssuer could only be used with --admin-mode cluster. In MAS 9.3+, the internal issuer is always Issuer (namespace-scoped, operator-managed), so issuerKind now only controls the external/public issuer — making it something the CLI can derive automatically from the user's DNS provider and routing choices rather than prompting for it explicitly.

This PR version-gates all issuerKind logic on 9.3.0. On 9.3+, --mas-issuer-kind is no longer accepted as a CLI flag (a fatal error is raised if passed), and issuerKind is derived automatically: ClusterIssuer when a DNS provider (Cloudflare, CIS, Route53) is configured, Issuer when Let's Encrypt HTTP-01 is chosen in path mode or when no DNS provider is set. The old validation that blocked ClusterIssuer in namespaced/minimal modes is removed for 9.3+ since the internal issuer is no longer affected by this field. The DNS integration restriction in namespaced/minimal modes is also scoped to 9.2 only — on 9.3+ customers can use a ClusterIssuer for external certs regardless of admin mode. On 9.2, all existing validation and prompt behaviour is preserved unchanged.

Related Issues

Testing

These changes are for MAS 9.3+ versions.
Install MAS without DNS integration (default domain) then it will use Issuer automatically:
Screenshot 2026-09-24 at 1 10 35 PM

Install MAS with DNS integration (custom domain) then it will use ClusterIssuer automatically:
Screenshot 2026-09-24 at 1 09 43 PM

Install MAS with Let's encrypt enabled for path routing mode then it will use Issuer automatically
Screenshot 2026-09-24 at 1 12 14 PM

If by mistake someone passes the --mas-issue-kind flag to the CLI for a MAS 9.3 install:
Screenshot 2026-09-24 at 1 07 59 PM

@praiyani6789
praiyani6789 marked this pull request as ready for review September 24, 2026 11:05
@praiyani6789
praiyani6789 requested a review from a team as a code owner September 24, 2026 11:05

@IanBoden IanBoden left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems like something we should be able to add unit tests for

@praiyani6789
praiyani6789 merged commit 2bdf9db into master Oct 7, 2026
12 of 13 checks passed
@praiyani6789
praiyani6789 deleted the pr.kind-temp branch October 7, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants