Skip to content

docs: administration: transport-security: document tls.verify_client_cert and tls.verify interaction - #2730

Merged
eschabell merged 1 commit into
fluent:masterfrom
eschabell:docs-tls-verify-client-cert-5.1.3
Oct 9, 2026
Merged

eschabell merged 1 commit into
fluent:masterfrom
eschabell:docs-tls-verify-client-cert-5.1.3

Conversation

@eschabell

@eschabell eschabell commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator
  • Extend the tls.verify_client_cert row with the tls.verify interaction:
    from v5.1.3, enabling it forces certificate validation even when
    tls.verify is off, and Fluent Bit warns when both are combined.
  • Add a v5.1 upgrade note covering the behavior change. Listeners that
    set tls.verify off with tls.verify_client_cert on previously accepted
    any client, and now reject clients without a CA-signed certificate.
  • Fix a pre-existing THe typo in the v1.1 Tag section.

Summary by CodeRabbit

  • Documentation
    • Clarified that in v5.1.3 and later, enabling tls.verify_client_cert requires client certificates to pass validation even when tls.verify is off. Fluent Bit warns when both settings are used and rejects clients without a certificate signed by the configured CA.
    • Added guidance to remove tls.verify_client_cert to accept clients without certificates.
    • Corrected a capitalization typo in the Kubernetes filter upgrade notes.

…cert and tls.verify interaction

  - Extend the tls.verify_client_cert row with the tls.verify interaction:
    from v5.1.3, enabling it forces certificate validation even when
    tls.verify is off, and Fluent Bit warns when both are combined.
  - Add a v5.1 upgrade note covering the behavior change. Listeners that
    set tls.verify off with tls.verify_client_cert on previously accepted
    any client, and now reject clients without a CA-signed certificate.
  - Fix a pre-existing THe typo in the v1.1 Tag section.

Signed-off-by: Eric D. Schabell <eric@schabell.org>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 49759a2f-ac6f-4046-a713-7660d211cac4
📥 Commits

Reviewing files that changed from the base of the PR and between ca2da90 and ea8821e.

📒 Files selected for processing (2)
  • administration/transport-security.md
  • installation/upgrade-notes.md

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The transport security reference and upgrade notes document how tls.verify_client_cert behaves when tls.verify is off in v5.1.3 and later. The upgrade notes also correct a capitalization typo.

Changes

TLS documentation

Layer / File(s) Summary
Document TLS client certificate behavior
administration/transport-security.md, installation/upgrade-notes.md
The reference and upgrade notes state that tls.verify_client_cert forces certificate validation when tls.verify is off, and that Fluent Bit logs a warning. The upgrade note states that clients without a certificate signed by the configured CA are rejected and advises removing tls.verify_client_cert to accept clients without certificates. It also corrects a capitalization typo.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to ea882

The documentation accurately reflects the verified TLS behavior, with no established merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the documentation change and the interaction it explains.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@eschabell eschabell self-assigned this Sep 25, 2026
@eschabell eschabell added waiting-on-review Waiting on a review from mainteners 5.1.3 labels Sep 25, 2026
@eschabell

Copy link
Copy Markdown
Collaborator Author

Set as draft waiting on 5.1.3 release.

@eschabell
eschabell marked this pull request as ready for review October 6, 2026 17:57
@eschabell
eschabell requested review from a team and patrick-stephens as code owners October 6, 2026 17:57
@eschabell

Copy link
Copy Markdown
Collaborator Author

@patrick-stephens ready for review, 5.1.3 dropped.

@eschabell
eschabell merged commit 6bf8871 into fluent:master Oct 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

5.1.3 waiting-on-review Waiting on a review from mainteners

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant