Skip to content

Add support for Strimzi-native Configurable RSA Keys - #13121

Draft
kyguy wants to merge 1 commit into
strimzi:mainfrom
kyguy:configurable-rsa-keys
Draft

kyguy wants to merge 1 commit into
strimzi:mainfrom
kyguy:configurable-rsa-keys

Conversation

@kyguy

@kyguy kyguy commented Sep 2, 2026

Copy link
Copy Markdown
Member

Type of change

  • Enhancement / new feature

Description

Adds a keySize field to CertificateAuthority allowing users to configure the RSA key size for both root and leaf certificates, defaulting to 4096 bits. This addresses compliance requirements (BSI, eIDAS, NIST) that mandate RSA keys larger than the previously hardcoded 2048-bit leaf key size.

Implements: https://github.com/strimzi/proposals/blob/main/153-configurable-ca-key-size.md

Addresses: #12769

Checklist

  • Update documentation
  • Update CHANGELOG.md (if present)
  • Reference relevant issue(s) and close them after merging
  • Write tests
  • Make sure all tests pass
  • Try your changes inside a Kubernetes cluster, not just from unit tests
  • AI assistance was used to create this PR (see the Strimzi AI policy)

@snyk-io

snyk-io Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@kyguy
kyguy force-pushed the configurable-rsa-keys branch 3 times, most recently from 97aa2f5 to 685c22d Compare September 22, 2026 15:55
@codecov

codecov Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 86.36364% with 3 lines in your changes missing coverage. Please review.
✅ Project coverage is 80.78%. Comparing base (d8b42c6) to head (0f63fae).

Files with missing lines Patch % Lines
...mzi/operator/cluster/model/EntityUserOperator.java 75.00% 0 Missing and 1 partial ⚠️
...java/io/strimzi/operator/common/ca/InternalCa.java 66.66% 1 Missing ⚠️
...a/io/strimzi/operator/user/UserOperatorConfig.java 66.66% 1 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               main   #13121      +/-   ##
============================================
+ Coverage     80.75%   80.78%   +0.02%     
- Complexity     6806     6813       +7     
============================================
  Files           360      360              
  Lines         23352    23365      +13     
  Branches       3174     3176       +2     
============================================
+ Hits          18858    18875      +17     
+ Misses         3254     3253       -1     
+ Partials       1240     1237       -3     
Files with missing lines Coverage Δ
.../main/java/io/strimzi/certs/OpenSslCertIssuer.java 81.23% <100.00%> (+0.05%) ⬆️
...n/java/io/strimzi/operator/common/ca/CaConfig.java 97.05% <100.00%> (+0.39%) ⬆️
...io/strimzi/operator/user/model/KafkaUserModel.java 84.23% <ø> (ø)
...imzi/operator/user/operator/KafkaUserOperator.java 88.66% <100.00%> (+0.07%) ⬆️
...mzi/operator/cluster/model/EntityUserOperator.java 96.03% <75.00%> (-0.69%) ⬇️
...java/io/strimzi/operator/common/ca/InternalCa.java 66.45% <66.66%> (ø)
...a/io/strimzi/operator/user/UserOperatorConfig.java 67.91% <66.66%> (-0.03%) ⬇️

... and 4 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@scholzj

scholzj commented Sep 22, 2026

Copy link
Copy Markdown
Member

@kyguy Just FYI ... the #13017 is pretty close to being merged. I think we will now aim at merging that first and then rebasing this PR on top of that. Sorry.

@kyguy kyguy added this to the 1.3.0 milestone Sep 22, 2026
@scholzj scholzj modified the milestones: 1.3.0, 1.4.0 Sep 26, 2026
Signed-off-by: Kyle Liberti <kliberti.us@gmail.com>
@kyguy
kyguy force-pushed the configurable-rsa-keys branch from 685c22d to 0f63fae Compare September 29, 2026 02:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants