This message was deleted.
# harvester
a
This message was deleted.
b
This is more of a
fluentd
thing than a Harvester thing, which I only point out because the chances are lower that someone has the same workflow. The biggest thing is that just because you've added the certificate chain in Harvester's settings, doesn't mean that the certs are injected into ALL workloads. It's likely only throwing it into workloads that's actually generated/covered by Harvester. I think** it might actually throw them into the nodes under
/etc/ssl/certs
? But you'd need to verify that. You'll probably need to do one of the following: • Mount in that path from the host (if you want to only to manage the certs in one place) • Add the CA cert to your fluentd helm chart. • Disable ssl checks for fluentd all together.
.spec.s3.ssl_verify_peer='false'
fwiw, I think MinIO went EOL and isn't accepting new PRs anymore. You might think about migrating to a new s3 provider. (We use ceph rgw)
g
Hey, Thanks a lot for the detailed explanation — that really helped me understand what's going on. Also, I appreciate you pointing out that MinIO is EOL — I had actually missed that. I was already considering moving away from it, so this pretty much confirmed the decision. We're currently leaning towards RustFS as a replacement. Thanks again for your help! @bland-article-62755
b
good luck!